Description
UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Address Bar
Action: Apply Update
AI Analysis

Impact

Google Chrome versions prior to 153.0.8010.36 contain a UI misrepresentation flaw in the UrlFormatting component. A remote attacker can craft a domain name that appears legitimate in the address bar, enabling a phishing attack that deceives users into believing they are visiting a trusted site. The weakness is classified as CWE‑451, exposing sensitive browsing context information to the user.

Affected Systems

All installations of Google Chrome with a version older than 153.0.8010.36 are affected, regardless of operating system. The flaw exists on all platforms where those versions are running.

Risk and Exploitability

Exploitation requires the victim to interact with a link or page controlled by the attacker; the attacker must convince the user to click on a crafted URL. This user‑interaction requirement is inferred from the description of the vulnerability. The CVSS score of 5.4 rates it as Medium severity, and the EPSS score of <1% suggests a low, but non‑zero, likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it can still facilitate credential theft or phishing if users are deceived.

Generated by OpenCVE AI on September 9, 2026 at 22:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to the latest stable release (153.0.8010.36 or newer).
  • Enable Chrome’s Safe Browsing feature to detect and block spoofed or malicious sites.
  • Educate users to verify the domain shown in the address bar, look for the padlock icon, and avoid clicking links from unfamiliar sources.

Generated by OpenCVE AI on September 9, 2026 at 22:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Spoofed Address Bar via Crafted Domain in Chrome URL Formatting

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Spoofed Address Bar via Crafted Domain in Chrome URL Formatting

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in UrlFormatting in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof address bar via a crafted domain name. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:41:50.701Z

Reserved: 2026-09-08T22:40:59.267Z

Link: CVE-2026-87567

cve-icon Vulnrichment

Updated: 2026-09-09T19:41:43.179Z

cve-icon NVD

Status : Modified

Published: 2026-09-09T01:17:14.407

Modified: 2026-09-09T20:20:58.537

Link: CVE-2026-87567

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T00:30:14Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information