Junglewise Threat Intelligence

CVE-2026-17958: Google Chrome UI spoofing in Views

CVE-2026-17958 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's user interface component could allow a remote attacker to misrepresent or spoof parts of the browser's visual display. By tricking a user into visiting a specially crafted website, an attacker could potentially deceive them into performing unintended actions or disclosing information by mimicking legitimate browser elements. This issue primarily impacts the integrity of the user's browsing experience and could be used in phishing attempts.

Technical details

A UI spoofing vulnerability exists in the 'Views' component of Google Chrome due to an inappropriate implementation. A remote attacker can exploit this by enticing a user to visit a malicious, specially crafted HTML page. Successful exploitation allows the attacker to manipulate or spoof the browser's user interface elements, potentially leading to user confusion or phishing attacks. The vulnerability is addressed in Google Chrome version 151.0.7922.72. Chromium has assigned this a security severity of Low.

Affected products

  • Google Chrome Prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats