Description
Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Google Chrome’s Global Media Controls enables a remote attacker to construct a malicious HTML page that can visually mimic legitimate UI elements. The incorrect implementation allows the attacker to spoof the user interface without executing arbitrary code. The potential consequence is a phishing‑style trick where a user may believe they are interacting with a trustworthy control and inadvertently reveal information or trigger unintended actions.

Affected Systems

Google Chrome browsers prior to version 151.0.7922.72 are affected. The vulnerability disappears in the 151.0.7922.72 release and all later builds.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability that exploitation is occurring today. The vulnerability is not yet listed in CISA’s KEV catalog. The likely attack vector is a remote attacker hosting a crafted HTML page that a victim visits; upon loading the page, the spoofed controls can deceive the user. Because no code execution or privilege escalation is possible, the risk is confined to user deception but can still facilitate phishing or unauthorized interactions.

Generated by OpenCVE AI on August 2, 2026 at 05:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 151.0.7922.72 or newer
  • Review web links and avoid opening suspicious or unsolicited HTML pages that request media control access
  • Monitor Google's release notes and apply newer patches as they become available

Generated by OpenCVE AI on August 2, 2026 at 05:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Incorrect security UI in Global Media Controls
Weaknesses CWE-1021
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

threat_severity

Low


Thu, 30 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Global Media Controls in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T19:21:30.593Z

Reserved: 2026-07-27T23:37:12.914Z

Link: CVE-2026-17983

cve-icon Vulnrichment

Updated: 2026-07-30T19:21:27.964Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:17:02.907

Modified: 2026-08-03T16:38:42.443

Link: CVE-2026-17983

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:25:54Z

Links: CVE-2026-17983 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:00:08Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information