Description
Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-10-06
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Clickjacking
Action: Patch
AI Analysis

Impact

Clickjacking in the EVP (Event‑Vector Processing) component of Google Chrome prior to 155.0.8059.39 allows a web‑based attack to cause a user to interact with hidden or masqueraded user interface elements. An attacker can embed a maliciously crafted HTML page that causes the victim to click a button or link that performs an unintended action, or displays UI elements that do not match what is actually presented. The weakness is classified as CWE-1021. The Chromium security team rated the vulnerability as medium severity.

Affected Systems

All desktop installations of Google Chrome running a version older than 155.0.8059.39 are affected. Mobile or other non‑desktop Chrome environments that rely on a different code base are not listed as impacted by this entry.

Risk and Exploitability

The flaw can be leveraged by a remote attacker who hosts a malicious web page and tricks a user into visiting it. Because the exploit depends on user interaction, the risk of successful exploitation is bounded by the likelihood that a user will open a compromised site. The CVSS score of 5.4 indicates moderate severity. No EPSS score is presently available and the vulnerability is not listed in CISA’s KEV catalog, which suggests there is currently no widespread, publicly reported exploitation. Nevertheless, the lack of an EPSS score does not eliminate the possibility of exploitation, and why prompt patching is advised.

Generated by OpenCVE AI on October 7, 2026 at 12:40 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 155.0.8059.39 or newer across all affected systems
  • Enable automatic updates so the browser receives security patches promptly
  • Consider installing reputable browser extensions that provide click‑jacking protection

Generated by OpenCVE AI on October 7, 2026 at 12:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 07 Oct 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 07 Oct 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Clickjacking in EVP
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

threat_severity

Moderate


Tue, 06 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
Description Clickjacking in EVP in Google Chrome prior to 155.0.8059.39 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-1021
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-10-07T10:30:14.937Z

Reserved: 2026-10-06T16:36:17.818Z

Link: CVE-2026-106356

cve-icon Vulnrichment

Updated: 2026-10-07T10:22:12.881Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-06T19:18:04.500

Modified: 2026-10-07T11:17:16.413

Link: CVE-2026-106356

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-10-06T18:41:24Z

Links: CVE-2026-106356 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T12:45:16Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames