Google Chrome Picture In Picture UI Spoofing Vulnerability

Vulnerability

A UI spoofing vulnerability has been identified in Google Chrome, specifically in the Picture In Picture feature. This issue affects Chrome versions prior to 139.0.7258.66. The vulnerability arises from an inappropriate implementation that allows remote attackers to manipulate user interface elements, provided they can convince a user to perform certain gestures on a specially crafted HTML page.

Impact

Exploitation of this vulnerability could lead to UI spoofing, where an attacker can create a misleading interface that deceives the user.

Remediation

Users can update to Google Chrome version 139.0.7258.66 or later to address this vulnerability.

Added: Aug 7, 2025, 2:28 AM
Updated: Aug 7, 2025, 2:28 AM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
4.2
remediation
7.7
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.