Executive brief
Google Chrome is a widely used web browser for accessing the internet. A vulnerability in the browser's download interface could allow a malicious website to trick users into performing unintended actions by misrepresenting security information. This could lead to a user unknowingly downloading or executing harmful files under the impression they are interacting with a legitimate security prompt.
Technical details
A UI spoofing vulnerability exists in the Downloads component of Google Chrome prior to version 147.0.7727.55. The flaw stems from an incorrect implementation of security UI elements, which can be manipulated by a remote attacker using a crafted HTML page. Exploitation requires the attacker to convince a user to perform specific UI gestures, such as clicking or dragging, which then allows the attacker to misrepresent critical security information. This is classified as CWE-451 (User Interface Misrepresentation of Critical Information). The issue has been addressed in Chrome version 147.0.7727.55 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2025-05-24: disclosed: Reported by Farras Givari
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
- 2026-04-08: advisory