Description
UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User interface spoofing enabling social engineering attacks
Action: Apply Patch
AI Analysis

Impact

A crafted HTML page can manipulate the Chrome file dialog’s visual elements so that a malicious website can present fake prompts or buttons to the user. By misrepresenting the UI, an attacker can trick users into believing they are interacting with legitimate system interfaces, potentially causing them to grant credentials, confirm downloads, or execute unintended actions. The vulnerability does not by itself allow arbitrary code execution; it merely exploits human trust in the browser’s UI.

Affected Systems

Google Chrome browsers older than version 155.0.8059.39 are affected, including all releases before this patch. The flaw is present in the file dialog rendering logic of the Chrome UI component and can be triggered from any webpage that the user visits in these versions.

Risk and Exploitability

The flaw is exploitable without the need for local code execution, relying on a socially engineered user interacting with a malicious webpage. No exploit probability metric is available, and the issue is not listed in the CISA KEV catalog. The CVSS score of 5.4 indicates medium severity. Because the attacker must host a crafted page and lure a user to open it, the likelihood of widespread exploitation is limited, but the potential for targeted phishing remains significant.

Generated by OpenCVE AI on October 7, 2026 at 02:47 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later
  • Configure Chrome to apply automatic updates so that future security patches are installed automatically
  • If automatic updates cannot be enabled, check for available updates manually and install the latest release

Generated by OpenCVE AI on October 7, 2026 at 02:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 03:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing Through Manipulated File Dialog in Chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in File in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:58.574Z

Reserved: 2026-10-06T16:33:56.181Z

Link: CVE-2026-106265

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:39.692Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:53.990

Modified: 2026-10-07T13:53:16.650

Link: CVE-2026-106265

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T05:15:12Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information