CVE-2026-11175
Google · Chrome on Android
An incorrect security UI implementation in the Messages component of Google Chrome on Android enables remote attackers to perform UI spoofing via a malicious HTML page.
Executive summary
A high-severity UI spoofing vulnerability in Google Chrome on Android can lead to unauthorized user deception regarding message security contexts.
Vulnerability
The flaw exists due to an incorrect security UI implementation within the Messages feature. By hosting a crafted HTML page, an unauthenticated remote attacker can present a misleading security context to the user, potentially facilitating social engineering or phishing.
Business impact
The CVSS score of 8.8 reflects the high risk associated with UI spoofing in modern browsers. This vulnerability could be leveraged to bypass user trust, leading to the compromise of sensitive communications or the inadvertent disclosure of information to malicious actors.
Remediation
Immediate Action: Update Google Chrome on Android to version 149.0.7827.53 or later.
Proactive Monitoring: Monitor for phishing reports or unusual browser behavior that deviates from standard security indicators.
Compensating Controls: Utilize enterprise-grade mobile security solutions that filter malicious URLs and block access to known phishing domains.
Exploitation status
Public Exploit Available: false
Analyst recommendation
Security teams must prioritize the deployment of the latest Chrome update to patch this UI vulnerability. Maintaining updated browser versions is critical to defending against deceptive UI attacks that target user trust.