You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve 2026 3942
About this tag
CVE-2026-3942 is a security vulnerability in the Picture-in-Picture (PiP) component of Chrome and Chromium browsers, classified as an incorrect security UI issue that enables UI spoofing via a crafted HTML page. The flaw was addressed in the Chrome/Chromium 146 release line, with patches documented in Google's Chrome release notes and public vulnerability trackers. Microsoft Edge, which is built on Chromium, also ingested the fix. Discussions on WindowsForum cover the technical details, affected versions, and mitigation steps for users and IT administrators managing Chromium-based browsers on Windows systems.
Chrome and Chromium teams have assigned CVE-2026-3942 to an Incorrect security UI vulnerability in the Picture‑in‑Picture (PiP) component that can be used for UI spoofing via a crafted HTML page — the bug was fixed upstream in the Chrome/Chromium 146 release line and is documented in Google’s...