Executive brief
A security flaw in Google Chrome for Android and Mac could allow a malicious website to misrepresent security information in the browser's download interface. By tricking a user into visiting a specially crafted webpage, an attacker could spoof the user interface to hide warnings or provide false information about a file being downloaded. This could lead users to inadvertently download and open malicious files they would otherwise have avoided.
Technical details
A UI spoofing vulnerability exists in the Downloads component of Google Chrome for Android and Mac. The flaw stems from an incorrect security UI implementation that can be manipulated by a remote attacker using a crafted HTML page. By leveraging this vulnerability, an attacker can present misleading security information or hide legitimate warnings during the file download process. Exploitation requires a user to visit a malicious website (User Interaction). The issue is resolved in version 148.0.7778.168.
Affected products
- Google Chrome prior to 148.0.7778.168
Timeline
- 2025-05-16: disclosed: Reported by Alesandro Ortiz
- 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
- 2026-05-14: advisory: NVD publication date