Executive brief
A vulnerability in Google Chrome's OptimizationGuide component could allow a remote attacker to perform UI spoofing. This occurs when an attacker who has already compromised a browser's rendering process uses a specially crafted webpage to deceive users. Such an attack could be used to trick users into revealing sensitive information or performing unintended actions by misrepresenting the browser's user interface.
Technical details
A vulnerability exists in the OptimizationGuide component of Google Chrome due to insufficient validation of untrusted input. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by serving a crafted HTML page. This allows the attacker to perform UI spoofing, potentially bypassing security indicators or misrepresenting browser state to the user. The issue is addressed in Chrome version 148.0.7778.216 and later.
Affected products
- Google Chrome Prior to 148.0.7778.216
Timeline
- 2026-05-27: patched: Stable channel update released for desktop
- 2026-05-28: disclosed: NVD publication date