Executive brief
A security issue in Google Chrome for Windows could allow a malicious website to misrepresent its identity. By tricking the browser's permission interface, an attacker could perform domain spoofing, potentially leading users to believe they are interacting with a trusted site when they are not. This could be used to facilitate phishing attacks or unauthorized data entry.
Technical details
A vulnerability classified as User Interface (UI) Misrepresentation of Critical Information (CWE-451) exists in the Permissions component of Google Chrome on Windows. The flaw stems from an incorrect security UI implementation that allows a remote attacker to perform domain spoofing. To exploit the vulnerability, an attacker must entice a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent the domain associated with browser permissions, potentially bypassing user-level security checks or facilitating phishing. The issue is resolved in Google Chrome version 147.0.7727.55.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-12: disclosed: Reported by daffainfo
- 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 release
- 2026-04-08: advisory: NVD publication date