Description
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing (Phishing Risk)
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is an incorrect authorization check in Chrome's isolated origins handling that lets a remote attacker craft an HTML page to spoof user interface elements. The attacker can make legitimate UI controls appear in a fake context, potentially leading to credential theft or deceptive input collection. This flaw does not allow code execution but grants persuasive fraud capabilities against users. The weakness is identified as CWE‑863. The likely attack vector is a crafted web page opened by the victim in Chrome, as confirmed by the Chromium release notes.

Affected Systems

Google Chrome browsers prior to version 153.0.8010.36 are affected. No other vendors or products are listed in the CNA data. The flaw applies to any Chrome installation running the affected builds; product details such as specific platforms or builds are not provided, so any installation of Chrome running an affected version could be vulnerable.

Risk and Exploitability

The CVSS score of 5.4 indicates a medium severity. The EPSS score is < 1%, indicating a very low publicly available exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Attack exploitation requires the victim to open a maliciously crafted page in Chrome; no privileged or local conditions are needed. Therefore the risk is moderate due to the potential for phishing and credential compromise, but it does not provide remote code execution or broader system compromise.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 153.0.8010.36 or later, which fixes the incorrect authorization check in isolated origins.
  • Ensure that automatic updates are enabled so future patches are applied without manual intervention.
  • Monitor web browsing activity for unexpected UI elements and educate users about phishing risks, especially when visiting unfamiliar websites.

Generated by OpenCVE AI on September 9, 2026 at 22:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 19:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 22:45:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing Vulnerability Allowing Remote Attackers to Fake Interface Elements

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing Vulnerability Allowing Remote Attackers to Fake Interface Elements

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-863
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:41:11.492Z

Reserved: 2026-09-08T22:39:53.705Z

Link: CVE-2026-87540

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:36.889Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:11.487

Modified: 2026-09-10T18:45:25.273

Link: CVE-2026-87540

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:00:10Z

Weaknesses