CVE-2026-2318
vulnerability analysis and mitigation

Overview

CVE-2026-2318 is a UI spoofing vulnerability caused by an inappropriate implementation in the PictureInPicture (PiP) feature of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Shaheen Fazim on 2024-09-02 and publicly disclosed on February 10–11, 2026, when Google released Chrome 145 to the stable channel. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Microsoft MSRC).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's PictureInPicture subsystem. An attacker can exploit this by hosting a crafted HTML page that manipulates the PiP overlay window to display misleading UI elements, but only after convincing the victim to perform specific UI gestures (e.g., clicking or interacting with page elements). This social-engineering precondition means the attack is network-delivered but requires user interaction, limiting its exploitability compared to zero-click vulnerabilities. Bug details remain restricted pending broad user adoption of the patch (Chrome Releases).

Impact

Successful exploitation allows a remote attacker to perform UI spoofing, deceiving users about the actual content or state of the browser interface — for example, displaying a fake login prompt or security dialog within the PiP window. The integrity impact is rated High, as users could be misled into submitting credentials or approving actions under false pretenses, enabling social engineering or credential harvesting. There is no direct confidentiality or availability impact, and the vulnerability does not enable code execution or lateral movement on its own (Chrome Releases).

Exploitation steps

  1. Craft a malicious HTML page: Develop a webpage that abuses Chrome's PictureInPicture API to render a deceptive overlay window — for example, a fake browser security warning, login form, or permission dialog.
  2. Lure the target: Distribute the malicious page via phishing email, malicious advertisement, or compromised website to attract victims using a vulnerable version of Chrome (prior to 145.0.7632.45).
  3. Trigger user interaction: Design the page to prompt the victim into performing specific UI gestures (e.g., clicking a button, playing a video) that activate the PiP window with the spoofed UI.
  4. Execute the social engineering attack: Once the PiP overlay is displayed, the victim sees a convincing fake interface (e.g., a credential prompt) and may submit sensitive information or approve a malicious action, believing it to be legitimate browser UI.
  5. Harvest results: Collect submitted credentials or use the approved action to further the attack chain (Chrome Releases).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser to unknown domains following interaction with a PiP-enabled webpage; form submissions to suspicious or newly registered domains.
  • Logs: Browser history or proxy logs showing visits to pages that programmatically invoke the PictureInPicture API in unusual ways; repeated access to the same page with varying query parameters.
  • Process: Chrome renderer processes spawning PiP windows on pages that are not media-streaming sites (e.g., news, video platforms); unusual JavaScript activity invoking requestPictureInPicture() on non-video elements.

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac); users should update immediately via Chrome's built-in update mechanism. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory. No configuration-based workaround is available; upgrading to the patched version is the only recommended remediation. Organizations can also consider restricting access to untrusted web content or disabling PictureInPicture functionality via enterprise policy in sensitive environments as a temporary measure (Chrome Releases, Microsoft MSRC).

Community reactions

Security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress covered the Chrome 145 release, noting the 11 security fixes including CVE-2026-2318 alongside higher-severity RCE-class vulnerabilities. Coverage generally characterized CVE-2026-2318 as a medium-severity issue requiring user interaction, with less urgency than the High-severity flaws patched in the same release. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management