Executive brief
A vulnerability in Google Chrome's Blink rendering engine allowed attackers to bypass security policies and spoof the browser's user interface. By tricking a user into visiting a specially crafted website, an attacker could display misleading information or fake interface elements to facilitate phishing or other social engineering attacks. This could lead to users inadvertently providing sensitive information to a malicious site.
Technical details
A policy bypass vulnerability exists in the Blink rendering engine of Google Chrome prior to version 147.0.7727.55. The flaw is categorized as an authorization bypass through a user-controlled key (CWE-639), which allows a remote, unauthenticated attacker to manipulate the browser's user interface. By convincing a user to load a malicious HTML page, the attacker can perform UI spoofing, potentially misrepresenting the origin or state of a web page. This vulnerability requires user interaction (visiting the site) and is reachable over the network. Google has addressed this issue in the stable channel update for desktop.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2025-07-08: other: Vulnerability reported to Chromium project
- 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
- 2026-04-08: disclosed: CVE published