
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3927 is an incorrect security UI vulnerability in the PictureInPicture feature of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by Barath Stalin K on January 11, 2026, and publicly disclosed on March 10–11, 2026, as part of the Chrome 146 stable channel release. The vulnerability affects all Google Chrome versions prior to 146.0.7680.71 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Feedly).
The vulnerability is classified under CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's PictureInPicture overlay fails to correctly render or enforce security UI indicators when processing certain HTML content. An attacker can craft a malicious HTML page that, when visited by a user, causes the PictureInPicture window to display misleading or spoofed security UI elements. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium bug tracker references issue 474948986 for this vulnerability (Chrome Releases).
Successful exploitation allows a remote attacker to spoof security-relevant UI elements within Chrome's PictureInPicture overlay, potentially deceiving users into believing they are interacting with a trusted interface. This could facilitate social engineering attacks such as credential phishing, fake security warnings, or misleading permission prompts. The vulnerability has no direct impact on confidentiality or availability (CVSS scores both as None), but poses a low integrity risk by enabling deceptive user interactions (Feedly).
Update Google Chrome to version 146.0.7680.71 or later on all platforms (Windows, Mac, Linux), which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update referencing this CVE (Microsoft MSRC). Organizations should ensure automated patch management is in place to deploy Chrome updates promptly. No configuration-based workaround is available; upgrading is the only remediation.
The Chrome 146 release addressing this vulnerability received coverage from security news outlets such as GBHackers, which noted the update addressed 29 vulnerabilities in total (GBHackers). The vulnerability was assigned a $3,000 bug bounty reward by Google, reflecting its Medium severity classification. No significant independent researcher commentary or social media discussion specific to CVE-2026-3927 has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."