Executive brief
A vulnerability in Google Chrome's fullscreen mode could allow a malicious website to display deceptive information to users. By manipulating the browser's interface, an attacker could trick a user into thinking they are on a legitimate site or interacting with a trusted system prompt. This type of 'UI spoofing' is often used in phishing attacks to steal login credentials or sensitive personal information.
Technical details
An issue was discovered in Google Chrome's Fullscreen component prior to version 148.0.7778.168. The vulnerability stems from an incorrect implementation of security UI elements when the browser is in fullscreen mode. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Once the page enters fullscreen mode, the attacker can spoof or hide critical security indicators, potentially leading to user confusion or successful phishing attempts. The fix is included in the Stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2024-05-29: disclosed: Reported by external researchers Wolfgang Ettlinger and Alexander Hurbean
- 2026-05-12: patched: Fixed in version 148.0.7778.168
- 2026-05-14: advisory: NVD publication date