Description
Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-02-11
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing
Action: Patch
AI Analysis

Impact

An inappropriate implementation of the file‑input element in Google Chrome allows a remote attacker who can persuade a user to perform specific UI gestures to perform UI spoofing via a specially crafted web page. Based on the description, it is inferred that the attacker must engage a user in simple clicking or selecting actions on the page. The attacker can hijack the user’s attention and force the browser to display a misleading file‑picker or similar UI, potentially making the user believe they are interacting with a legitimate element while the attacker controls it. This flaw has a Medium severity rating in Chromium and does not provide arbitrary code execution; its primary impact is the circumvention of the user’s intent, which could facilitate phishing or credential theft.

Affected Systems

Google Chrome versions older than 145.0.7632.45 are affected. The flaw resides in the browser’s handling of file‑input elements, so any operating system that hosts Chrome—Windows, macOS, Linux—is at risk when out‑of‑date versions are installed.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1 %, indicating a low likelihood of widespread exploitation at this time. The attack requires a social‑engineering scenario in which a user visits a malicious web page and performs simple UI gestures such as clicking a button. Based on the description, it is inferred that the attacker must rely on user interaction, and no high‑privilege or unconstrained remote code execution is possible. The vulnerability is not listed in the CISA KEV catalog, suggesting that large‑scale exploitation has not yet been observed.

Generated by OpenCVE AI on April 18, 2026 at 18:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install Chrome version 145.0.7632.45 or newer on all devices to eliminate the insecure file‑input behavior.
  • If an immediate upgrade is not possible, use enterprise policy or a browser extension to block or warn about suspicious file‑picker prompts, limiting the use of the file‑input element.
  • Educate users about the risk of file‑picker prompts from unfamiliar sites and advise them to verify the authenticity of such prompts before proceeding.

Generated by OpenCVE AI on April 18, 2026 at 18:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6135-1 chromium security update
History

Fri, 13 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Thu, 12 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-451
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Thu, 12 Feb 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Inappropriate implementation in File input
References
Metrics threat_severity

None

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

threat_severity

Moderate


Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 11 Feb 2026 18:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in File input in Google Chrome prior to 145.0.7632.45 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-02-12T15:11:25.872Z

Reserved: 2026-02-10T21:51:45.968Z

Link: CVE-2026-2320

cve-icon Vulnrichment

Updated: 2026-02-12T15:09:03.011Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-11T19:15:52.160

Modified: 2026-02-13T14:52:29.383

Link: CVE-2026-2320

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-02-10T00:00:00Z

Links: CVE-2026-2320 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T18:15:06Z

Weaknesses