PT-2026-24876 · Google+1 · Google Chrome+1
Portsniffer443
·
Published
2025-08-03
·
Updated
2026-05-15
·
CVE-2026-3928
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.71
Description
A flaw exists in Google Chrome where insufficient policy enforcement in extensions could allow an attacker to perform UI spoofing. Specifically, if a user is tricked into installing a malicious extension, the attacker can manipulate the Chrome extension to perform a user interface spoofing attack.
Recommendations
Update Google Chrome to version 146.0.7680.71 or later.
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome
Red Os