Executive brief
A vulnerability in Google Lens within the Google Chrome browser could allow a malicious website to misrepresent its identity or display deceptive content. This occurs when an attacker who has already gained partial control over a browser's rendering process uses a specially crafted webpage to spoof the user interface. If successful, this could lead to users being tricked into interacting with malicious elements or providing sensitive information under false pretenses.
Technical details
This vulnerability is classified as a UI spoofing flaw resulting from an inappropriate implementation within the Google Lens component of Google Chrome. The attack requires a precondition where the attacker has already compromised the renderer process, typically through a separate vulnerability. By leveraging this foothold, the attacker can serve a crafted HTML page that manipulates the browser's user interface elements associated with Google Lens. This could be used to deceive users regarding the origin or nature of the content they are viewing. The issue is addressed in Google Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date