PT-2026-24889 · Google+1 · Google Chrome+1

Barath Stalin K

·

Publicado

2026-01-12

·

Atualizado

2026-05-20

·

CVE-2026-3942

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 146.0.7680.71
Description An incorrect security user interface in the PictureInPicture feature in Google Chrome prior to version 146.0.7680.71 allowed a remote attacker to perform UI spoofing through a crafted HTML page. The Chromium security severity is rated as Low. The attack involves manipulating an HTML page to create a deceptive user interface within the PictureInPicture mode.
Recommendations Update Google Chrome to version 146.0.7680.71 or later.

Correção

UI Misrepresentation of Critical Information

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-05757
CVE-2026-3942
OPENSUSE-SU-2026:10376-1
OPENSUSE-SU-2026:20372-1

Produtos afetados

Google Chrome
Red Os