Description
UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-17
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Crafted HTML Pages
Action: Patch
AI Analysis

Impact

This vulnerability is classified as CWE‑451, indicating an information exposure flaw. It occurs in the WebAppInstalls component of Google Chrome prior to version 153.0.8010.52, where a remote attacker can render UI elements that do not represent the actual page content. By delivering a specially crafted HTML page, the attacker can spoof interface elements—such as buttons or prompts—deceiving users into interacting with deceptive components. The impact is limited to user interface manipulation; the flaw does not provide direct code execution, data exfiltration, or system compromise. Instead, the main risk is social engineering fraud, phishing, or click‑jacking scenarios.

Affected Systems

Google Chrome browsers on all platforms that are running a version earlier than 153.0.8010.52 are affected. Updated releases beyond this version incorporate the fix and are not impacted.

Risk and Exploitability

The CVSS score of 5.4 is in the medium range, yet Chromium categorizes the flaw as low severity. Its EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to deliver a crafted web page that a victim visits and then socially engineer the user into interacting with the spoofed UI elements. No privileged or remote code execution capabilities are needed for exploitation, but a determined attacker could still misuse the deception for credential theft or other social engineering attacks.

Generated by OpenCVE AI on September 19, 2026 at 19:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Google Chrome to version 153.0.8010.52 or later.
  • Disable or block the WebAppInstalls feature until the patch is applied, if possible via flags or extensions.
  • Avoid interacting with unexpected prompts or UI elements on unfamiliar web pages until the update is installed.

Generated by OpenCVE AI on September 19, 2026 at 19:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4790-1 chromium security update
Debian DSA Debian DSA DSA-6508-1 chromium security update
History

Sat, 19 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Title UI Spoofing via WebAppInstalls in Google Chrome

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Fri, 18 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 17 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-18T13:30:16.587Z

Reserved: 2026-09-17T19:35:05.096Z

Link: CVE-2026-93386

cve-icon Vulnrichment

Updated: 2026-09-18T13:10:40.261Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-17T21:17:55.953

Modified: 2026-09-18T17:18:45.147

Link: CVE-2026-93386

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T19:15:17Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information