Description
Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Published: 2026-05-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is an insufficient validation of untrusted input in Chrome’s TabGroups feature, which allows a malicious actor to send crafted network traffic that causes the browser to render spoofed UI elements. Based on the description, it is inferred that this can trick users into interacting with false prompts or content, potentially leading to phishing or other social engineering attacks. The weakness is classified as CWE‑20 and is described as low severity by Chromium’s internal metric.

Affected Systems

All desktop builds of Google Chrome with a version number less than 148.0.7778.96 are affected, as the vulnerability is fixed in the 148.0.7778.96 stable update. Users on earlier releases should be aware that the TabGroups feature is vulnerable until they upgrade to 148.0.7778.96 or later.

Risk and Exploitability

An attacker would need to deliver malicious network traffic to a victim’s Chrome instance, meaning the attack vector is remote but limited to network communication to an otherwise legitimate browser session. The EPSS score of approximately 0.00053 (<1%) and the lack of listing in CISA’s KEV catalog indicate that large‑scale exploitation has not been observed. Given the low severity rating from Chromium's internal metric, lack of exploit evidence, and a published CVSS score of 5.4, the overall risk remains low, albeit still capable of enabling UI‑based phishing.

Generated by OpenCVE AI on May 7, 2026 at 15:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 148.0.7778.96 or later.
  • Ensure Chrome’s auto‑update feature is enabled so future patches are applied automatically.
  • Avoid visiting untrusted or suspicious websites until the browser is updated, as they may attempt to exploit the TabGroups input validation flaw.

Generated by OpenCVE AI on May 7, 2026 at 15:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 16:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome TabGroups Enables UI Spoofing

Thu, 07 May 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome TabGroups

Wed, 06 May 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 21:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Untrusted Input in Chrome TabGroups
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in TabGroups in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:48:09.070Z

Reserved: 2026-05-05T22:59:32.574Z

Link: CVE-2026-8003

cve-icon Vulnrichment

Updated: 2026-05-06T21:22:14.279Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:51.290

Modified: 2026-05-07T14:00:54.447

Link: CVE-2026-8003

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T16:00:12Z

Weaknesses