Description
Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Interface Spoofing
Action: Immediate Update
AI Analysis

Impact

This vulnerability arises from incorrect authorization checks within Chrome’s navigation handling. When a renderer process has been compromised by a remote attacker, the attacker can craft a malicious HTML page that tricks the browser into displaying forged UI elements. The attacker can thus deceive users into interacting with counterfeit controls or gaining information through deceptive prompts, compromising the confidentiality of contextual information and potentially influencing user actions.

Affected Systems

Google Chrome browsers prior to version 153.0.8010.36 are affected. The issue exists in all platforms where the Chrome renderer processes run under the default security model.

Risk and Exploitability

The flaw has a CVSS score of 4.2, corresponding to Medium severity. The exploit requires an attacker to first gain control of a renderer process, typically through compromising a webpage or leveraging another vulnerability that allows code execution in that process. Once the renderer is compromised, an attacker can deliver crafted content to the user to spoof interface elements. The EPSS score is <1%, indicating a very low exploitation probability, and the issue is not listed in the CISA KEV catalog, suggesting that the threat of widespread exploitation is currently limited, but the potential impact on users is significant if the renderer is compromised.

Generated by OpenCVE AI on September 9, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or newer.
  • Ensure Chrome automatic updates are enabled so that security patches are applied as soon as they are released.
  • Avoid visiting or interacting with untrusted web pages that could host malicious HTML designed to spoof UI elements.

Generated by OpenCVE AI on September 9, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows UI Spoofing in Google Chrome

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 05:00:00 +0000

Type Values Removed Values Added
Title Incorrect Authorization Allows UI Spoofing in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Navigation in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:44:09.135Z

Reserved: 2026-09-08T22:22:27.252Z

Link: CVE-2026-87432

cve-icon Vulnrichment

Updated: 2026-09-09T18:58:56.994Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:16:59.340

Modified: 2026-09-09T20:29:47.787

Link: CVE-2026-87432

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses