Description
UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-09
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: User fraud via UI spoofing
Action: Patch
AI Analysis

Impact

Google Chrome’s payment user interface can be misrepresented by a remote attacker through a crafted HTML page. The flaw, classified as CWE‑451 and CWE‑1021, allows an attacker to replace genuine payment prompts with counterfeit elements that look legitimate, potentially causing users to unknowingly submit payment information or confirm transactions. The vulnerability does not provide a pathway to execute code or gain elevated privileges; it simply deceives the user through visual manipulation, and the Chromium team rates it as Medium severity.

Affected Systems

All desktop installations of Google Chrome that are running versions earlier than 153.0.8010.36 are affected. Versions 153.0.8010.36 and later contain the fix that blocks the UI misrepresentation attack.

Risk and Exploitability

The most likely attack vector is a malicious webpage that a user visits, which uses the payment UI to display spoofed dialogs. Because the flaw resides in the rendering pipeline for payment pages, it does not require additional user input beyond normal browsing. The CVSS score of 5.4 indicates a medium severity risk, and the EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploitation yet. The Medium severity rating indicates a moderate risk of financial fraud if a user falls for the deception. No elevated privileges or system compromise are required.

Generated by OpenCVE AI on September 9, 2026 at 13:49 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.36 or newer.
  • Ensure automatic updates are enabled so future patches are applied promptly.
  • Verify that payment prompts display expected company branding and do not show unexpected or unfamiliar text, and be cautious about proceeding with transactions on untrusted sites.

Generated by OpenCVE AI on September 9, 2026 at 13:49 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6506-1 chromium security update
History

Wed, 09 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
Vendors & Products Google
Google chrome

Wed, 09 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 09 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title UI Element Spoofing in Google Chrome Payment Flow chromium-browser: chromium-browser: UI misrepresentation in Payments
Weaknesses CWE-1021
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Wed, 09 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Title UI Element Spoofing in Google Chrome Payment Flow

Wed, 09 Sep 2026 01:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Payments in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-09T19:40:40.587Z

Reserved: 2026-09-08T22:43:32.695Z

Link: CVE-2026-87635

cve-icon Vulnrichment

Updated: 2026-09-09T19:37:35.641Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-09T01:17:21.880

Modified: 2026-09-09T20:28:19.883

Link: CVE-2026-87635

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-09-09T00:09:55Z

Links: CVE-2026-87635 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:45:05Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information