Description
Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: n/a
EPSS: n/a
KEV: No
Impact: UI Spoofing
Action: Update Chrome
AI Analysis

Impact

An incomplete cleanup in the GetUserMedia function of Google Chrome before version 155.0.8059.39 allows a remote attacker who has already compromised the renderer process to spoof user interface elements through a specially crafted HTML page. The flaw results in deceptive UI overlays that can lead users to trust malicious input, effectively enabling phishing or social engineering attacks. This is a weakness in access control and related to CWE‑459, which describes weak or broken access control.

Affected Systems

Google Chrome on all platforms prior to version 155.0.8059.39 is affected. The issued stable channel update addresses the issue and is available through the Chrome update mechanism.

Risk and Exploitability

The vulnerability requires an attacker to first compromise the renderer process, a condition that limits the attack surface but does not eliminate it. With that foothold, the attacker can manipulate the UI presented to the user. The EPSS score is not available, but the Chromium security severity is Medium, and the issue is not listed in CISA KEV. The attack vector is remote via a crafted web page, so users remain at risk while using older Chrome versions or until the patch is applied.

Generated by OpenCVE AI on October 6, 2026 at 22:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 155.0.8059.39 or later via the stable channel update
  • Disable or restrict the GetUserMedia API for sites that do not require it using site settings or browser extensions
  • Educate users to verify the authenticity of UI elements and remain cautious of phishing attempts

Generated by OpenCVE AI on October 6, 2026 at 22:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 06 Oct 2026 22:30:00 +0000

Type Values Removed Values Added
Title Chrome GetUserMedia UI Spoofing Vulnerability

Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup in GetUserMedia in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-459
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T18:41:29.233Z

Reserved: 2026-10-06T16:33:49.572Z

Link: CVE-2026-106262

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:17:53.593

Modified: 2026-10-06T19:57:00.457

Link: CVE-2026-106262

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T22:15:06Z

Weaknesses