Description
UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via WebOTP
Action: Patch Chrome
AI Analysis

Impact

Google Chrome versions prior to 155.0.8059.39 suffered a UI misrepresentation flaw in the WebOTP feature. A remote attacker could serve a crafted HTML page that tricks the browser into displaying spoofed user interface elements, potentially leading users to inadvertently provide sensitive information. The weakness is classified as CWE-451, indicating that information is revealed through incorrect UI or data presentation. The impact is primarily the potential for social‑engineering attacks where a victim is misled into interacting with malicious content. No elevated privileges are required beyond normal user interaction with the vulnerable browser page.

Affected Systems

The affected product is Google Chrome. Versions earlier than 155.0.8059.39 on all platforms are vulnerable, including the stable channel of the desktop client. No other Google products are listed as impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 5.4 and is considered medium severity in Chromium’s internal scoring. EPSS is not available and the flaw is not listed in CISA’s KEV catalog. The attack vector is remote, but requires a victim to open a malicious page that triggers WebOTP. Because the flaw is an UI spoofing issue rather than a code‑execution or privilege‑escalation flaw, the likelihood of widespread exploitation is lower, yet the consequence is serious in an environment where users rely on OTP prompts.

Generated by OpenCVE AI on October 7, 2026 at 01:07 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or later
  • Set the browser to receive automatic updates to ensure the fix is applied promptly
  • If an upgrade cannot occur immediately, disable the WebOTP feature via local policy or block access to the affected API endpoints

Generated by OpenCVE AI on October 7, 2026 at 01:07 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 01:30:00 +0000

Type Values Removed Values Added
Title WebOTP UI Spoofing in Google Chrome

Tue, 06 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in WebOTP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-06T20:45:58.196Z

Reserved: 2026-10-06T16:34:16.499Z

Link: CVE-2026-106282

cve-icon Vulnrichment

Updated: 2026-10-06T20:43:34.007Z

cve-icon NVD

Status : Analyzed

Published: 2026-10-06T19:17:55.933

Modified: 2026-10-07T13:44:02.470

Link: CVE-2026-106282

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T03:30:10Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information