Executive brief
Google Chrome is a widely used web browser. A vulnerability in the browser's user interface (UI) could allow a remote attacker to trick users by spoofing or misrepresenting parts of the browser's visual interface. This could lead to users being deceived into performing unintended actions or trusting malicious content, though it requires the attacker to have already compromised a specific part of the browser's internal processing.
Technical details
This vulnerability is classified as a User Interface (UI) Misrepresentation (CWE-451) due to insufficient policy enforcement in the browser's UI components. The flaw allows a remote attacker to perform UI spoofing, provided they have already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can manipulate the browser's interface to mislead the user. The issue was addressed in Google Chrome version 147.0.7727.55 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-25: other: Reported by Tianyi Hu
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 release
- 2026-04-08: advisory: Initial NVD publication