Description
Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-02-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Interface Spoofing
Action: Patch
AI Analysis

Impact

Inappropriate implementation of the Picture‑in‑Picture feature in Google Chrome allowed a remote attacker to persuade a user to perform specific interface gestures that result in UI spoofing. By loading a crafted HTML page, the attacker can overlay deceptive elements or misleading controls that trick the user into believing they are interacting with legitimate content. This flaw is classified as CWE‑451 and can lead to phishing or other social‑engineering attacks.

Affected Systems

The vulnerability affects Google Chrome versions older than 145.0.7632.45 on all major operating systems, including macOS, Linux, and Windows. As the Picture‑in‑Picture mode operates across platforms, the threat is applicable to every user running an impacted Chrome build regardless of OS.

Risk and Exploitability

Severity is medium with a CVSS score of 6.5 and an EPSS probability of less than 1 %, indicating a relatively low chance of exploitation at this time, and it is not listed in CISA’s KEV catalog. Exploitation requires a malicious web page that induces the user to perform UI gestures; the attack is user‑initiated and relies on social engineering. The most likely vector is a compromised or malicious website that prompts the user to engage with Picture‑in‑Picture controls.

Generated by OpenCVE AI on April 17, 2026 at 20:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 145.0.7632.45 or later.
  • Enable Chrome’s auto‑update feature to receive future security patches automatically.
  • Restrict or disable Picture‑in‑Picture mode via Chrome policy or flags if the feature is not required in your environment.

Generated by OpenCVE AI on April 17, 2026 at 20:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6135-1 chromium security update
History

Fri, 13 Feb 2026 17:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 12 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Thu, 12 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Inappropriate implementation in PictureInPicture
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-02-12T15:35:56.235Z

Reserved: 2026-02-10T21:51:44.856Z

Link: CVE-2026-2318

cve-icon Vulnrichment

Updated: 2026-02-12T15:35:03.950Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-11T19:15:51.920

Modified: 2026-02-13T17:29:01.080

Link: CVE-2026-2318

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-10T00:00:00Z

Links: CVE-2026-2318 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T20:30:15Z

Weaknesses