Description
Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Chrome Downloads
Action: Immediate Patch
AI Analysis

Impact

An incorrect authorization check in the Downloads feature of Google Chrome before version 153.0.8010.36 allows a remote attacker who has already compromised the renderer process to deliver a crafted HTML page that can spoof user interface elements. This flaw permits the attacker to display counterfeit UI components, potentially misleading users about download actions or other interactions. The vulnerability is a classic instance of improper authorization (CWE‑863).

Affected Systems

Google Chrome users running any version prior to 153.0.8010.36 are affected. The issue is limited to the Downloads functionality and requires the attacker to have control over the renderer process to deliver the malicious page.

Risk and Exploitability

The CVSS score of 4.2 indicates a medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires prior compromise of the renderer process; once achieved, the attacker can craft content that triggers UI spoofing. The risk is moderate because the threat does not allow remote code execution, but the impact on user trust and potential for phishing remains significant.

Generated by OpenCVE AI on September 9, 2026 at 21:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later, ensuring the download authorization check is correctly enforced.
  • If an immediate upgrade is not feasible, apply a Chrome policy that disables or restricts the Downloads UI for untrusted contexts, preventing spoofed elements from rendering.
  • Educate users to verify the authenticity of download dialogs and report any suspicious UI behavior, and consider monitoring browser logs for anomalous UI rendering events.

Generated by OpenCVE AI on September 9, 2026 at 21:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Downloads UI Spoofing via Improper Authorization chromium-browser: chromium-browser: Incorrect authorization in Downloads
Weaknesses CWE-1021
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome Downloads UI Spoofing via Improper Authorization

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:44:40.012Z

Reserved: 2026-09-08T22:37:50.530Z

Link: CVE-2026-87465

cve-icon Vulnrichment

Updated: 2026-09-09T18:59:23.480Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:03.010

Modified: 2026-09-09T20:30:19.710

Link: CVE-2026-87465

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:40Z

Links: CVE-2026-87465 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-863

    Incorrect Authorization