PT-2026-24889 · Google · Google Chrome
Barath Stalin K
·
Published
2026-01-12
·
Updated
2026-03-17
·
CVE-2026-3942
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Google Chrome versions prior to 146.0.7680.71
Description
An incorrect security user interface in the PictureInPicture feature in Google Chrome prior to version 146.0.7680.71 allowed a remote attacker to perform UI spoofing through a crafted HTML page. The Chromium security severity is rated as Low. The attack involves manipulating an HTML page to create a deceptive user interface within the PictureInPicture mode.
Recommendations
Update Google Chrome to version 146.0.7680.71 or later.
Fix
UI Misrepresentation of Critical Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Google Chrome