Description
UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Interface Spoofing
Action: Update
AI Analysis

Impact

The vulnerability lies in the TabStrip UI component of Google Chrome, where a crafted HTML page can cause the browser to render misleading UI elements. This allows a remote attacker to trick users into interacting with deceptive controls, potentially leading to fraud or social engineering. The weakness is identified as CWE‑451.

Affected Systems

Affected product is Google Chrome on desktop platforms, versions earlier than 154.0.8037.92. Users running any pre‑154.0.8037.92 release are susceptible.

Risk and Exploitability

The CVSS score of 5.4 places the issue in the moderate range. No EPSS score is available, and it is not listed in the CISA KEV catalog. The attack vector is remote and does not require privileged or local access; a malicious webpage hosted by the attacker can trigger the issue. Users can mitigate by updating to a patched Chrome release.

Generated by OpenCVE AI on September 30, 2026 at 08:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Chrome 154.0.8037.92 or later.
  • Enable automatic updates so new security patches are installed promptly.
  • Use Chrome Safety Check and Safe Browsing to detect phishing or spoofing sites, and educate users about warning signs of UI deception.

Generated by OpenCVE AI on September 30, 2026 at 08:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 16:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 30 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation in TabStrip Enables HTML-Based UI Spoofing

Wed, 30 Sep 2026 00:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 20:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in TabStrip in Google Chrome prior to 154.0.8037.92 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T20:51:55.528Z

Reserved: 2026-09-28T21:44:28.828Z

Link: CVE-2026-102314

cve-icon Vulnrichment

Updated: 2026-09-29T20:49:42.529Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-29T20:17:14.543

Modified: 2026-09-30T15:44:11.267

Link: CVE-2026-102314

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T08:30:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information