Description
Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI spoofing
Action: Patch
AI Analysis

Impact

Improper input validation in Chrome interstitial pages permits remote attackers to craft HTML that displays spoofed UI components such as warning banners or dialog boxes. Because interstitials can be rendered by the browser with an elevated envelope, the attacker can cause the victim to see UI that appears legitimate but is actually controlled by the attacker. Based on the description, it is inferred that the attacker could influence user actions by manipulating the perceived authenticity of UI elements.

Affected Systems

Google Chrome browsers on all operating systems running a version earlier than 153.0.8010.36 are vulnerable. The defect was corrected in Chrome 153.0.8010.36 and later.

Risk and Exploitability

The CVSS score is 5.4, classified as Medium. The EPSS score is <1% indicating a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to serve a malicious HTML page to a victim; because the flaw is client‑side the attack vector is Remote (web‑based). The impact is limited to the targeted user’s browser session, though spoofed UI could mislead the user.

Generated by OpenCVE AI on September 9, 2026 at 22:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 153.0.8010.36 or later on all machines.
  • Enforce Chrome update policy in enterprise environments to ensure all devices receive the latest security patches.
  • Verify that no custom interstitial pages or extensions capable of spoofing UI are installed on affected devices.

Generated by OpenCVE AI on September 9, 2026 at 22:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 10 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Interstitials Enables UI Spoofing

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Title Improper Input Validation in Chrome Interstitials Enables UI Spoofing

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:43:22.698Z

Reserved: 2026-09-08T22:41:58.092Z

Link: CVE-2026-87599

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:41.074Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:17.903

Modified: 2026-09-10T13:44:29.447

Link: CVE-2026-87599

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T12:15:16Z

Weaknesses
  • CWE-20

    Improper Input Validation