Description
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing
Action: Apply Patch
AI Analysis

Impact

This vulnerability is caused by improper input validation in FedCM, the Federated Credential Management API, in Google Chrome versions prior to 153.0.8010.36. When an attacker gains control of the renderer process, they can deliver a crafted HTML page that causes the browser to display spoofed UI elements. The result is a UI spoofing attack that enables phishing or other social‑engineering exploits, potentially misleading users into submitting sensitive information or interacting with malicious content. The weakness is an insecure input validation flaw (CWE-20).

Affected Systems

All users running Google Chrome on the stable channel before version 153.0.8010.36 are impacted. The vulnerability was discovered in the Chrome renderer component used across all supported operating systems.

Risk and Exploitability

The risk level is Medium according to the Chromium security severity assessment and the CVSS base score is 4.2, confirming a medium severity. Exploitation requires the attacker to have already compromised the renderer process. It is inferred that common causes of such renderer compromise include memory corruption or code‑execution flaws, though this is not explicitly stated in the CVE. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Given the need for a renderer compromise, the likelihood of successful exploitation is limited but not negligible in environments where other renderer vulnerabilities exist. The attacker can only spoof UI elements; there is no direct remote code execution or data exfiltration capability disclosed by the CVE statement. Nonetheless, the potential for phishing and user deception warrants prompt remediation.

Generated by OpenCVE AI on September 9, 2026 at 22:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or later.
  • Restrict or remove extensions with unnecessary renderer privileges to reduce the chance of a renderer compromise.
  • Maintain Chrome’s sandboxing and site isolation features so that even if the renderer is compromised, the impact is contained.

Generated by OpenCVE AI on September 9, 2026 at 22:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome FedCM UI Spoofing via Improper Input Validation

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 05:30:00 +0000

Type Values Removed Values Added
Title Chrome FedCM UI Spoofing via Improper Input Validation

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:42:49.521Z

Reserved: 2026-09-08T22:38:05.109Z

Link: CVE-2026-87472

cve-icon Vulnrichment

Updated: 2026-09-09T18:58:36.215Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:03.777

Modified: 2026-09-10T19:16:51.920

Link: CVE-2026-87472

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-20

    Improper Input Validation