
CVE-2026-3927 Incorrect security UI in PictureInPicture in Google Chrome prior to 146.0.7680.71 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium se… https://www.cve.org/CVERecord?id=CVE-2026-3927
Post summary
The text reports a UI spoofing flaw in Chrome’s PictureInPicture mode that can be triggered by a crafted HTML page, indicating a newly disclosed vulnerability.
