Junglewise Threat Intelligence

CVE-2026-17983: Google Chrome UI spoofing in Global Media Controls

CVE-2026-17983 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Global Media Controls—the interface used to manage audio and video playback—could allow a malicious website to spoof user interface elements. An attacker could use a specially crafted webpage to trick users into performing unintended actions by misrepresenting what is being displayed in the browser's media controls. This type of flaw is typically used in phishing or social engineering attacks to deceive users.

Technical details

A UI spoofing vulnerability exists in the Global Media Controls component of Google Chrome due to an inappropriate implementation. By enticing a user to visit a specially crafted HTML page, a remote attacker can manipulate or misrepresent the user interface elements within the media control overlay. This is classified by Chromium as a 'Low' severity issue. The vulnerability is addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats