UI Spoofing Vulnerability in Google Chrome by Google
CVE-2026-2318
6.5MEDIUM
What is CVE-2026-2318?
An inappropriate implementation in the PictureInPicture feature of Google Chrome prior to version 145.0.7632.45 enables remote attackers to manipulate user interface elements by convincing users to perform specific gestures. This exploit can be achieved through a carefully crafted HTML page, which may lead to deceptive representations of content on the browser, potentially compromising user trust and security.
Affected Version(s)
Chrome 145.0.7632.45