VYPR

PictureInPicture

by Google

CVEs (1)

  • CVE-2026-2318MedFeb 11, 2026
    risk 0.42cvss 6.5epss 0.00

    Inappropriate implementation in PictureInPicture in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)