Description
Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Fullscreen
Action: Update Chrome
AI Analysis

Impact

A confused‑deputy flaw in Chrome’s Fullscreen feature lets an attacker who has already compromised the renderer process craft HTML that can spoof user interface elements. The vulnerability does not provide direct code execution; it allows the attacker to trick users into interacting with elements appearing legitimate. The weakness is categorized as CWE‑441 – Confused Deputy.

Affected Systems

Chromium, specifically Google Chrome versions prior to 153.0.8010.36, are affected. Updated builds of Chrome that ship with the full‑screen request handling fix are not impacted.

Risk and Exploitability

Based on the description, the likely attack vector is a malicious page that a user is tricked into loading, which would give the attacker control of the renderer process; this prerequisite is non‑trivial. The EPSS score of < 1% combined with the CVSS score of 4.2 indicates a low likelihood of widespread exploitation and a low severity impact. The flaw is not listed in the CISA KEV catalog, corroborating its limited exploitability. As described, the vulnerability permits successful phishing or credential‑stealing attempts through spoofed UI elements.

Generated by OpenCVE AI on September 9, 2026 at 18:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later.
  • Restrict or disable full‑screen requests from unknown or untrusted sites by configuring Chrome’s Fullscreen settings or using extensions that enforce user confirmation.
  • Enable Chrome’s Safe Browsing and phishing detection to reduce risk of renderer compromise.

Generated by OpenCVE AI on September 9, 2026 at 18:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
Title Confused Deputy in Chrome Fullscreen Allows UI Spoofing via Compromised Renderer

Wed, 09 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Confused deputy in Fullscreen in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-441
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T15:05:24.384Z

Reserved: 2026-09-08T22:38:54.630Z

Link: CVE-2026-87502

cve-icon Vulnrichment

Updated: 2026-09-09T15:05:19.349Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:07.130

Modified: 2026-09-09T18:09:35.667

Link: CVE-2026-87502

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:15:16Z

Weaknesses
  • CWE-441

    Unintended Proxy or Intermediary ('Confused Deputy')