Description
Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing / Phishing
Action: Update Chrome
AI Analysis

Impact

This vulnerability involves incorrect reference resolution in the Accessibility module of Google Chrome on macOS, allowing a remote attacker to craft a malicious HTML page that can spoof UI elements. The flaw could mislead users into interacting with deceptive controls or content, potentially facilitating phishing or social‑engineering attacks. Chromium assigns a medium severity to the issue.

Affected Systems

The issue affects Google Chrome browsers running on macOS systems prior to version 153.0.8010.36. Any Chrome installation on those builds that processes HTML content from an unknown source is potentially vulnerable.

Risk and Exploitability

Based on the description that a crafted HTML page can trigger the flaw, it is inferred that the attack vector is remote and does not require local privilege escalation. The EPSS score indicates a very low likelihood of exploitation, with a probability of less than 1 percent. The CVSS score of 4.3 reflects a medium severity flaw, and the vulnerability is not listed in the CISA KEV catalog. Despite the medium severity rating, the vulnerability can be abused in phishing campaigns or malicious websites aimed at users of vulnerable Chrome versions, especially if accessibility features are enabled.

Generated by OpenCVE AI on September 9, 2026 at 22:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update all macOS installations of Google Chrome to version 153.0.8010.36 or later.
  • Disable or restrict Chrome’s Accessibility module for users who do not require it, using enterprise policies or local settings.
  • Ensure Chrome’s safe‑browsing is enabled and disable local file access via flags to reduce the ability of malicious HTML pages to exploit the vulnerability.

Generated by OpenCVE AI on September 9, 2026 at 22:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
Title Accessibility Reference Resolution Spoofing in Chrome on macOS

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Google
Google chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Incorrect reference resolution in Accessibility in Google Chrome on on Mac prior to 153.0.8010.36 allowed a remote attacker to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-706
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:43:52.572Z

Reserved: 2026-09-08T22:40:43.398Z

Link: CVE-2026-87562

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:42.832Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:13.880

Modified: 2026-09-09T20:21:09.487

Link: CVE-2026-87562

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T13:45:16Z

Weaknesses
  • CWE-706

    Use of Incorrectly-Resolved Name or Reference