Google Chrome
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*, +1 more
- < 139.0.7258.66
A UI spoofing vulnerability has been identified in Google Chrome, specifically in the Picture In Picture feature, prior to version 139.0.7258.66. This vulnerability allows remote attackers to manipulate user interface elements by convincing users to perform certain gestures on a crafted HTML page.
Exploitation of this vulnerability could lead to UI spoofing, where an attacker can create a misleading interface that appears legitimate, potentially tricking users into taking unintended actions.
Users can update to Google Chrome version 139.0.7258.66 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.