PT-2026-7644 · Google · Google Chrome

Shaheen Fazim

·

Published

2026-01-01

·

Updated

2026-02-19

·

CVE-2026-2318

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 145.0.7632.45
Description A flaw exists in the PictureInPicture functionality of Google Chrome. This issue could allow a remote attacker to perform UI spoofing by convincing a user to interact with a specially crafted HTML page through specific UI gestures. The security severity is rated as Medium.
Recommendations Update Google Chrome to version 145.0.7632.45 or later.

Fix

UI Misrepresentation of Critical Information

Weakness Enumeration

Related Identifiers

BDU:2026-01829
CVE-2026-2318
OPENSUSE-SU-2026:10201-1
OPENSUSE-SU-2026:20248-1

Affected Products

Google Chrome