Description
UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing of Password Prompts
Action: Update Chrome
AI Analysis

Impact

This vulnerability enables a remote attacker to deliver a malicious HTML page that forces Google Chrome on Android to display forged password prompts. The UI misrepresentation, identified as CWE‑451, lets the attacker trick users into entering credentials into a counterfeit dialog, compromising confidentiality of login information. The flaw is purely client‑side and depends on the browser rendering the crafted page.

Affected Systems

The affected product is Google Chrome for Android prior to version 153.0.8010.36. Devices running any older Chrome version are susceptible, while the 153.0.8010.36 stable channel update implements the necessary UI validation to prevent spoofing.

Risk and Exploitability

Chromium rates this issue with low severity (CVSS 5.4), and it is not listed in the CISA KEV catalogue. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The flaw can be exploited remotely by tricking a user into visiting a malicious page, making it suitable for phishing attempts against Android Chrome users who have not yet updated.

Generated by OpenCVE AI on September 9, 2026 at 22:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 153.0.8010.36 or later.
  • Ensure that automatic updates are enabled so that future security patches are applied without manual intervention.
  • Avoid entering sensitive credentials on unfamiliar or untrusted websites until the browser update is confirmed.

Generated by OpenCVE AI on September 9, 2026 at 22:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 10 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Title Android Chrome Password Prompt Spoof via Crafted Page

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:39:37.571Z

Reserved: 2026-09-08T22:41:22.022Z

Link: CVE-2026-87583

cve-icon Vulnrichment

Updated: 2026-09-09T19:35:30.278Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:16.150

Modified: 2026-09-10T13:47:36.223

Link: CVE-2026-87583

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:30:07Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information