Description
Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the PDF implementation of Google Chrome versions prior to 149.0.7827.53 allows an attacker who has already compromised the renderer process to deliver a crafted HTML page that can spoof the user interface. The weakness originates from inadequate input validation, categorized as CWE‑20. This flaw permits the attacker to replace or overlay legitimate UI elements with deceptive ones, potentially misleading users about the content or actions they are interacting with.

Affected Systems

Google Chrome browsers of any operating system version earlier than 149.0.7827.53 are affected. The vulnerability is tied to the PDF rendering component present in all standard Chrome releases.

Risk and Exploitability

No CVSS score is provided and the EPSS score is unavailable; the issue is not listed in CISA’s KEV catalog. The Chromium severity assessment labels it low. Exploitation requires an attacker to first gain control of the renderer process, after which they can serve malicious PDF content or a website that triggers the UI‑spoofing page. Because the prerequisite of renderer compromise limits the attack surface, the overall risk to typical users is considered low, but the potential for misleading UI remains a concern for environments where user trust is critical.

Generated by OpenCVE AI on June 5, 2026 at 02:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or later
  • Avoid opening PDF files from untrusted or unknown sources in Chrome
  • Enable Chrome’s Safe Browsing feature to help detect UI‑spoofing attempts

Generated by OpenCVE AI on June 5, 2026 at 02:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via PDF Rendering in Google Chrome

Fri, 05 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PDF in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:06:08.607Z

Reserved: 2026-06-04T17:11:08.201Z

Link: CVE-2026-11261

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T00:17:02.860

Modified: 2026-06-05T00:17:02.860

Link: CVE-2026-11261

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T02:15:29Z

Weaknesses