Inappropriate implementation in PictureInPicture in Google Chrome prior to 130.0.6723.58 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
- https://issues.chromium.org/issues/40076120
- https://github.com/fkie-cad/nvd-json-data-feeds