PT-2026-24889 · Google+1 · Google Chrome+1
Barath Stalin K
·
Publicado
2026-01-12
·
Atualizado
2026-05-20
·
CVE-2026-3942
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.71
Description
An incorrect security user interface in the PictureInPicture feature in Google Chrome prior to version 146.0.7680.71 allowed a remote attacker to perform UI spoofing through a crafted HTML page. The Chromium security severity is rated as Low. The attack involves manipulating an HTML page to create a deceptive user interface within the PictureInPicture mode.
Recommendations
Update Google Chrome to version 146.0.7680.71 or later.
Correção
UI Misrepresentation of Critical Information
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Google Chrome
Red Os