Executive brief
A vulnerability in Google Chrome on Windows could allow a malicious website to spoof parts of the browser's user interface. This could be used to trick users into performing unintended actions or believing they are on a legitimate site when they are not. To exploit this, an attacker would first need to have compromised a specific internal browser process.
Technical details
This vulnerability is classified as an inappropriate implementation in the UI (CWE-451) of Google Chrome on Windows. The flaw allows a remote attacker who has already achieved code execution within a compromised renderer process to perform UI spoofing. By using a specially crafted HTML page, the attacker can manipulate the browser's user interface to deceive the user. While the CVSS score is 4.2 (Medium), Chromium has assigned this a 'Critical' internal severity rating. The issue is addressed in Chrome version 148.0.7778.179 for Windows.
Affected products
- Google Chrome prior to 148.0.7778.179
Timeline
- 2026-04-20: disclosed: Reported by Google internal researchers
- 2026-05-19: patched: Fixed in version 148.0.7778.179
- 2026-05-20: advisory