CVE-2026-16422

7.5

Google · Chrome

Insufficient validation of untrusted input in Certificate in Google Chrome on Linux allows an attacker in a privileged network position to perform domain spoofing.

Executive summary

A high-severity domain spoofing vulnerability in Google Chrome on Linux could allow attackers in a privileged network position to undermine origin trust.

Vulnerability

This flaw involves insufficient validation of untrusted input within the certificate handling logic. It is an unauthenticated, network-adjacent attack that requires the adversary to be in a position to intercept or manipulate network traffic.

Business impact

Successful domain spoofing allows an attacker to deceive users by presenting fraudulent websites as legitimate, trusted entities. This is a significant risk for phishing, credential theft, and man-in-the-middle attacks. With a CVSS score of 7.5, this vulnerability represents a substantial threat to the integrity of secure communications.

Remediation

Immediate Action: Update Google Chrome on all Linux distributions to version 150.0.7871.182 or later.

Proactive Monitoring: Monitor network traffic for suspicious SSL/TLS certificate discrepancies and utilize tools to detect potential man-in-the-middle attempts.

Compensating Controls: Enforce the use of VPNs or encrypted tunnels to mitigate the risk of attackers achieving a privileged network position.

Exploitation status

Public Exploit Available: No (unknown).

Analyst recommendation

While this vulnerability requires specific network conditions, the potential for domain spoofing remains a high risk to organizational security. Administrators should update browser instances on Linux endpoints as part of their standard patch management cycle to prevent credential theft and impersonation attacks.

More Google CVEs