We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.
Please see our statement on Data Privacy.
Fullscreen API Spoofing and UI Redressing in the handling of Fullscreen API and UI rendering in OpenAI Operator SaaS on Web allows a remote attacker to capture sensitive user input (e.g., login credentials, email addresses) via displaying a deceptive fullscreen interface with overlaid fake browser controls and a distracting element (like a cookie consent screen) to obscure fullscreen notifications, tricking the user into interacting with the malicious site.
Reserved 2025-07-02 | Published 2025-07-10 | Updated 2025-07-10 | Assigner GoogleCWE-451 : User Interface (UI) Misrepresentation of Critical Information
github.com/...search/security/advisories/GHSA-mmgx-755h-wr74
Support options