
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3928 is an insufficient policy enforcement vulnerability in the Extensions component of Google Chrome that enables UI spoofing via a crafted malicious extension. It affects Google Chrome versions prior to 146.0.7680.71 and Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "portsniffer443" on 2025-08-03 and publicly disclosed on March 10–11, 2026, when Google released Chrome 146. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from insufficient enforcement of Chrome's extension policies that are intended to restrict what extensions can render or overlay in the browser UI. An attacker must first convince a target user to install a specially crafted Chrome extension — a social engineering precondition — after which the extension can manipulate or spoof browser UI elements in ways that violate expected policy boundaries. The Chromium issue tracker references bug ID 435980394 for this vulnerability, though full technical details remain restricted pending broad user patching (Chrome Releases).
Successful exploitation allows an attacker-controlled extension to perform UI spoofing, potentially displaying fake browser chrome, security indicators, or website overlays that appear legitimate to the user. This can facilitate credential theft, phishing, or other social engineering attacks by deceiving users into trusting fraudulent interfaces. Confidentiality and availability are not directly impacted; the primary risk is to integrity through user deception (Chrome Releases, Feedly).
%LOCALAPPDATA%\Google\Chrome\User Data\Default\Extensions\ on Windows or ~/.config/google-chrome/Default/Extensions/ on Linux) containing obfuscated JavaScript.Google has released Chrome 146.0.7680.71 (Linux) and 146.0.7680.71/72 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). As a complementary control, organizations should enforce extension allowlisting via enterprise policy (e.g., ExtensionInstallAllowlist) to prevent installation of unauthorized extensions, and educate users not to install extensions from untrusted sources.
GBHackers covered the broader Chrome 146 security update, noting it addressed 29 vulnerabilities including this one (GBHackers). Security community coverage was routine given the Medium severity rating and lack of active exploitation; no notable researcher commentary or significant social media discussion specific to CVE-2026-3928 was identified beyond standard vulnerability aggregator postings.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."