Description
Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-04
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation of permissions in Google Chrome versions prior to 149.0.7827.53 allows a remote attacker to deceive users through a crafted HTML page. The flaw exploits the browser’s permission dialog rendering, enabling UI spoofing where counterfeit dialog boxes or permission requests mimic legitimate Chrome prompts. While no direct data theft or code execution occurs, this manipulation can persuade users to grant permissions or reveal sensitive information, compromising trust and enabling social‑engineering attacks.

Affected Systems

All desktop builds of Google Chrome older than version 149.0.7827.53 are impacted, regardless of operating system. The vulnerability is present in every release before that specific version.

Risk and Exploitability

The flaw carries a Chromium security severity of Low, and its EPSS score is unavailable. An attacker only needs to provide a malicious web page that the browser will render, meaning the attack can be performed over the network in many environments. It is not listed in the CISA KEV catalog, but the potential for exploitation remains, particularly for phishing campaigns that rely on convincing UI elements.

Generated by OpenCVE AI on June 5, 2026 at 00:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 149.0.7827.53 or newer using the official update channel.
  • Maintain automatic updates so future patches are applied without manual intervention.
  • Educate users to verify the origin of permission prompts and refrain from granting permissions to suspicious pages.

Generated by OpenCVE AI on June 5, 2026 at 00:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 05 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Permissions Allow UI Spoofing in Google Chrome
First Time appeared Google
Google chrome
Weaknesses CWE-1028
Vendors & Products Google
Google chrome

Thu, 04 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-04T23:06:24.748Z

Reserved: 2026-06-04T17:11:19.891Z

Link: CVE-2026-11300

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-05T00:17:07.830

Modified: 2026-06-05T00:17:07.830

Link: CVE-2026-11300

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T01:00:15Z

Weaknesses