
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2318 is a UI spoofing vulnerability caused by an inappropriate implementation in the PictureInPicture (PiP) feature of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Shaheen Fazim on 2024-09-02 and publicly disclosed on February 10–11, 2026, when Google released Chrome 145 to the stable channel. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's PictureInPicture subsystem. An attacker can exploit this by hosting a crafted HTML page that manipulates the PiP overlay window to display misleading UI elements, but only after convincing the victim to perform specific UI gestures (e.g., clicking or interacting with page elements). This social-engineering precondition means the attack is network-delivered but requires user interaction, limiting its exploitability compared to zero-click vulnerabilities. Bug details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows a remote attacker to perform UI spoofing, deceiving users about the actual content or state of the browser interface — for example, displaying a fake login prompt or security dialog within the PiP window. The integrity impact is rated High, as users could be misled into submitting credentials or approving actions under false pretenses, enabling social engineering or credential harvesting. There is no direct confidentiality or availability impact, and the vulnerability does not enable code execution or lateral movement on its own (Chrome Releases).
requestPictureInPicture() on non-video elements.Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac); users should update immediately via Chrome's built-in update mechanism. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory. No configuration-based workaround is available; upgrading to the patched version is the only recommended remediation. Organizations can also consider restricting access to untrusted web content or disabling PictureInPicture functionality via enterprise policy in sensitive environments as a temporary measure (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress covered the Chrome 145 release, noting the 11 security fixes including CVE-2026-2318 alongside higher-severity RCE-class vulnerabilities. Coverage generally characterized CVE-2026-2318 as a medium-severity issue requiring user interaction, with less urgency than the High-severity flaws patched in the same release. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."