Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +2 more
- < 140.0.7339.80
A UI spoofing vulnerability has been identified in Google Chrome, specifically in the Permissions feature, prior to version 140.0.7339.80. This vulnerability allows remote attackers to manipulate user interface elements through a specially crafted HTML page. The issue arises from an inappropriate implementation in how permissions are handled, particularly with the Permission Element in the Chrome Permissions API.
Exploitation of this vulnerability could lead to user interface spoofing, where an attacker can create a misleading representation of the application or system, potentially tricking users into interacting with permission prompts that have been previously denied.
The vulnerability can be reproduced by creating an HTML page that uses the Permission Element and applies specific CSS styles, such as 'text-emphasis' and 'text-emphasis-position', to manipulate how permission prompts are displayed. If the styles are not properly reset in the Permission Element, it can create a false impression that a permission is available to be granted, even if it was previously denied.
Users should update to Google Chrome version 140.0.7339.80 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.