Description
UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Interface Spoofing
Action: Patch
AI Analysis

Impact

A flaw in the Paint module of Google Chrome allows an attacker to deliver a crafted web page that misrepresents user interface elements. The vulnerability can cause the browser to display harmless‑looking elements that actually invoke malicious actions, potentially tricking users into interacting with or accepting harmful content. The weakness is a UI misrepresentation flaw (CWE‑451) and does not provide direct code execution but enables deceptive presentation.

Affected Systems

The issue affects Google Chrome on all platforms running a version earlier than 155.0.8059.39. Users with these legacy builds are susceptible until the patch is applied.

Risk and Exploitability

The attack vector is remote; a malicious site can host an HTML page that exploits the Paint UI misrepresentation. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Though its CVSS score of 5.4 indicates Medium severity, the lack of a known exploit and the reliance on user interaction mean the risk is moderate but still relevant, especially for users who may not recognize spoofed UI elements.

Generated by OpenCVE AI on October 7, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later, the release that contains the security fix.
  • If an update is not immediately possible, disable or restrict the Paint feature in Chrome settings to remove the attack surface.
  • Educate users to verify the authenticity of UI elements and to avoid interacting with unexpected prompts or buttons on unfamiliar web pages.

Generated by OpenCVE AI on October 7, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 02:15:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Allowing Remote Attacker to Spoof UI Elements in Chrome Paint

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Allowing Remote Attacker to Spoof UI Elements in Chrome Paint
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Paint in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:58.330Z

Reserved: 2026-10-06T16:30:03.730Z

Link: CVE-2026-106182

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:35.940Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:44.170

Modified: 2026-10-06T21:17:05.203

Link: CVE-2026-106182

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:30:10Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information