Executive brief
A vulnerability in Google Chrome for Mac could allow an attacker to trick users into installing a malicious browser extension. Once installed, this extension can manipulate the browser's user interface, potentially leading users to believe they are interacting with legitimate sites or system prompts. This type of spoofing can be used to facilitate phishing attacks or unauthorized downloads.
Technical details
An inappropriate implementation in the Downloads component of Google Chrome on macOS allowed for UI spoofing. An attacker could exploit this by convincing a user to install a malicious Chrome Extension. Once active, the crafted extension could manipulate browser UI elements related to downloads, potentially misleading the user about the origin or nature of files. This issue was addressed in version 148.0.7778.168 for Mac.
Affected products
- Google Chrome Prior to 148.0.7778.168
Timeline
- 2025-09-04: disclosed: Reported by Farras Givari
- 2026-05-12: patched: Stable channel update released
- 2026-05-14: advisory: NVD publication date