Description
UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing
Action: Immediate Patch
AI Analysis

Impact

A flaw in the Geometry component of Google Chrome before version 153.0.8010.36 allows a remote attacker to craft an HTML page that misrepresents UI elements, effectively spoofing user interface components. This misrepresentation can lead to deceptive interactions, such as tricking users into trusting false prompts or buttons, and is classified as a medium severity vulnerability by Chromium security. The weakness involves improper handling of rendering metadata, as indicated by its CWE-451 classification.

Affected Systems

All installations of Google Chrome that are using a Geometry component prior to the 153.0.8010.36 release are affected. This includes stable channel builds older than the update referenced in the Chrome release blog. The vulnerability applies to any user who can load a malicious page in their browser, regardless of operating system. The affected product is Google Chrome; the vulnerable version range ends at 153.0.8010.35 and earlier.

Risk and Exploitability

The vulnerability is exploitable via a crafted web page, requiring the victim to visit the malicious site. Because the EPSS score is 0.00208 (~0.21%) and the flaw is not listed in CISA’s KEV catalog, known exploitation activity is not documented, but the attack vector is clear and the potential for social engineering is high. The medium severity index, with a CVSS score of 5.4, reflects the risk of user deception and the likelihood of the attacker’s success given the ease of page loading and the lack of defensive mitigations in the affected release.

Generated by OpenCVE AI on September 9, 2026 at 22:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or newer
  • Enable enterprise policy to auto‑update Chrome and block the use of older releases
  • Conduct user awareness training about phishing UI spoofing to reduce social engineering attacks

Generated by OpenCVE AI on September 9, 2026 at 22:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome Enabling Remote Attacker to Spoof UI Elements

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing Vulnerability in Google Chrome Enabling Remote Attacker to Spoof UI Elements

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:41:27.476Z

Reserved: 2026-09-08T22:37:30.059Z

Link: CVE-2026-87458

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:37.486Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:02.220

Modified: 2026-09-09T20:30:48.620

Link: CVE-2026-87458

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:15:17Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information