Description
UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing
Action: Patch Immediately
AI Analysis

Impact

The vulnerability allows a remote attacker to trick users into interacting with forged user interface components. By hosting a specially crafted HTML page, an attacker can present UI elements that appear to belong to Google Chrome, such as login prompts or permission dialogs. This spoofing can deceive users into revealing sensitive information, providing credentials, or granting permissions that they would not normally provide. The flaw is identified as CWE‑451, indicating that it results in unauthorized disclosure or misrepresentation.

Affected Systems

Google Chrome browsers on any platform updating before the release of version 153.0.8010.36 are affected. This includes desktop installations that have not yet applied the latest stable channel fix referenced in the Chrome release notes.

Risk and Exploitability

The CVSS score of 4.2 classifies the vulnerability as medium. The EPSS score is under 1%, and the vulnerability is not listed in CISA’s KEV database, indicating limited attack vector data at this time. The most likely exploitation path relies on a social engineering vector, where an attacker lures a user to a malicious web page or link. Once the user visits the page, the spoofed UI can be silently displayed, allowing the attacker to harvest credentials or other sensitive data. Because the vulnerability exploits only a visual trick and does not require code execution or elevated privileges, the scope of damage depends heavily on user susceptibility, but successful exploitation could result in credential theft or unauthorized data access.

Generated by OpenCVE AI on September 9, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later to remove the UI spoofing flaw.
  • Enable Chrome’s built‑in Safe Browsing feature to help detect and block phishing sites, reducing the chance of social‑engineering attacks.
  • Conduct user awareness training focused on recognizing unexpected or mismatched UI elements in web browsers.

Generated by OpenCVE AI on September 9, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Google Chrome

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:00:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted HTML in Google Chrome

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in UI in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:45:21.108Z

Reserved: 2026-09-08T22:40:38.927Z

Link: CVE-2026-87559

cve-icon Vulnrichment

Updated: 2026-09-09T19:45:07.323Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:13.553

Modified: 2026-09-09T20:22:45.730

Link: CVE-2026-87559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information