Junglewise Threat Intelligence

CVE-2026-9110: Google Chrome UI spoofing on Windows

CVE-2026-9110 · Severity: medium · CVSS 4.2 · Published 2026-05-20

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome on Windows could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are on a legitimate site when they are not. To exploit this, an attacker would first need to have compromised a specific internal browser process.

Technical details

This vulnerability is classified as an inappropriate implementation in the UI (CWE-451) of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform UI spoofing. By using a specially crafted HTML page, the attacker can manipulate the browser's user interface to deceive the user. While the CVSS score is 4.2 (Medium), Chromium has assigned this a 'Critical' internal severity rating. The issue is addressed in Chrome version 148.0.7778.179 for Windows.

Affected products

  • Google Chrome prior to 148.0.7778.179

Timeline

  • 2026-04-20: disclosed: Reported by Google internal researchers
  • 2026-05-19: patched: Fixed in version 148.0.7778.179
  • 2026-05-20: advisory

References

Related threats