Google Chrome Permissions UI Spoofing Vulnerability

Vulnerability

A UI spoofing vulnerability has been identified in Google Chrome, specifically in the Permissions feature, prior to version 140.0.7339.80. This vulnerability allows remote attackers to manipulate user interface elements through a specially crafted HTML page. The issue arises from an inappropriate implementation in how permissions are handled, particularly with the Permission Element in the Chrome Permissions API.

Impact

Exploitation of this vulnerability could lead to user interface spoofing, where an attacker can create a misleading representation of the application or system, potentially tricking users into interacting with permission prompts that have been previously denied.

Reproduction

The vulnerability can be reproduced by creating an HTML page that uses the Permission Element and applies specific CSS styles, such as 'text-emphasis' and 'text-emphasis-position', to manipulate how permission prompts are displayed. If the styles are not properly reset in the Permission Element, it can create a false impression that a permission is available to be granted, even if it was previously denied.

Remediation

Users should update to Google Chrome version 140.0.7339.80 or later, where this vulnerability has been fixed.

Added: Nov 8, 2025, 12:25 AM
Updated: Nov 8, 2025, 12:25 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
5.8
remediation
7.7
relevance
0.9
threat
6.4
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.