Executive brief
A vulnerability in Google Chrome's fullscreen mode could allow a malicious website to misrepresent its identity or display fake security information. By using a specially crafted webpage, an attacker could trick users into believing they are interacting with a legitimate site or a trusted browser interface. This type of attack is typically used for phishing or to deceive users into providing sensitive information.
Technical details
A UI spoofing vulnerability exists in the Fullscreen component of Google Chrome prior to version 147.0.7727.55. The flaw stems from an incorrect implementation of security UI elements when the browser is in fullscreen mode, which fails to properly prevent a malicious site from overlaying or mimicking trusted browser interface components. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to perform UI misrepresentation (CWE-451), potentially leading to phishing or other social engineering attacks. The issue is addressed in Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-02: other: Vulnerability reported to Chromium project
- 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
- 2026-04-08: advisory: NVD publication date