Executive brief
A vulnerability in the Google Chrome update component on Windows could allow a local attacker to display deceptive user interface elements. By using a specially crafted file, an attacker could trick users into performing unintended actions or disclosing information by spoofing legitimate browser prompts. This issue primarily affects the integrity of the browser's visual communication with the user.
Technical details
An inappropriate implementation vulnerability exists in the Updater component of Google Chrome on Windows. A local attacker can exploit this by placing or executing a malicious file on the system to trigger UI spoofing. This allows the attacker to misrepresent browser state or prompts to the user. The vulnerability is rated as Low severity by Chromium and was addressed in version 151.0.7922.72. Access to specific bug details is currently restricted by the vendor.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date