Google Chrome Incorrect Security UI in SplitView UI Spoofing Vulnerability

Vulnerability

A UI spoofing vulnerability has been identified in Google Chrome versions prior to 142.0.7444.59. This issue arises from an incorrect security user interface in SplitView, which allowed remote attackers to manipulate UI elements by convincing users to perform specific gestures. The exploitation involved using a crafted domain name to achieve the spoofing effect.

Impact

Exploitation of this vulnerability could lead to UI spoofing, where a remote attacker manipulates the user interface to mislead users or interfere with their interactions.

Remediation

Users can update to Google Chrome version 142.0.7444.59 or later to address this vulnerability.

Added: Nov 10, 2025, 8:28 PM
Updated: Nov 10, 2025, 10:34 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.4
remediation
7.7
relevance
0.9
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.