Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*
- < 132.0.6834.83
A race condition vulnerability has been identified in Google Chrome versions prior to 132.0.6834.83. This vulnerability allows remote attackers to perform UI spoofing by convincing users to engage in specific UI gestures on a crafted HTML page. The issue arises from improper handling of frame visibility, which can be exploited to mislead users interacting with certain interface elements.
Exploitation of this vulnerability can lead to UI spoofing, where an attacker manipulates the user interface to deceive users into interacting with elements in a misleading way.
The vulnerability can be reproduced by opening a specific HTML file that exploits the race condition in frame handling. After clicking a button that obscures the Google One Tap button, the focus can still be directed to the One Tap button, creating a clickjacking scenario.
Users should update to Google Chrome version 132.0.6834.83 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.