Google Chrome Race Condition Vulnerability in Frames Allowing UI Spoofing

Vulnerability

A race condition vulnerability has been identified in Google Chrome versions prior to 132.0.6834.83. This vulnerability allows remote attackers to perform UI spoofing by convincing users to engage in specific UI gestures on a crafted HTML page. The issue arises from improper handling of frame visibility, which can be exploited to mislead users interacting with certain interface elements.

Impact

Exploitation of this vulnerability can lead to UI spoofing, where an attacker manipulates the user interface to deceive users into interacting with elements in a misleading way.

Reproduction

The vulnerability can be reproduced by opening a specific HTML file that exploits the race condition in frame handling. After clicking a button that obscures the Google One Tap button, the focus can still be directed to the One Tap button, creating a clickjacking scenario.

Remediation

Users should update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
5.2
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.