Description
UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-09
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User Interface Spoofing
Action: Update Browser
AI Analysis

Impact

The vulnerability allows a remote attacker who has already compromised the browser renderer process to present fabricated UI elements on the Passwords page in Chrome for Android. This misrepresentation can trick a user into believing legitimate requests are genuine, enabling credential theft through social engineering without actually executing code outside the browser sandbox. The described weakness relies on improper visual validation of sensitive UI elements and thus exposes users to phishing attacks.

Affected Systems

Google Chrome for Android versions earlier than 153.0.8010.36 are affected. Any device running a pre‑153.0.8010.36 release can be vulnerable if an attacker can render a malicious page while running the renderer process.

Risk and Exploitability

The CVSS base score of 4.2 (Low) reflects that this is a low‑severity issue, and the EPSS score of <1% suggests that widespread exploitation is unlikely. The vulnerability requires that the attacker has already compromised the browser’s renderer process to deliver a crafted page, limiting the attack surface to sophisticated threat actors. Because the prerequisite of renderer compromise exists, the overall risk remains modest, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, credential theft remains possible if an attacker can inject malicious content into a Chrome browser session.

Generated by OpenCVE AI on September 9, 2026 at 22:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on Android to release 153.0.8010.36 or later
  • Remove any untrusted applications that could serve malicious web content to the device
  • Maintain the latest Android OS security updates to preserve renderer sandbox integrity

Generated by OpenCVE AI on September 9, 2026 at 22:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Thu, 10 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Thu, 10 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 23:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Passwords in Chrome on Android

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 06:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Passwords in Chrome on Android

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Passwords in Google Chrome on on Android prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:39:52.550Z

Reserved: 2026-09-08T22:43:02.357Z

Link: CVE-2026-87624

cve-icon Vulnrichment

Updated: 2026-09-09T18:52:07.301Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:20.660

Modified: 2026-09-10T13:41:21.193

Link: CVE-2026-87624

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T11:45:11Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information