Description
UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-29
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI spoofing enabling social engineering
Action: Immediate Patch
AI Analysis

Impact

A remote attacker can craft a web page that, when viewed in Chrome, displays user interface elements inside the ExtensionsMenu that do not actually exist. This misrepresentation can make a user believe that a trusted extension or request is active when it is not, allowing the attacker to trick the user into taking unintended actions, such as approving a malicious extension or clicking a deceptive link. The flaw is a user interface spoofing vulnerability identified as CWE‑451.

Affected Systems

All users running Google Chrome versions earlier than 154.0.8037.57 on any platform are affected. The flaw lies in the ExtensionsMenu rendering logic and impacts any Chrome browser that implements this menu interface.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate risk; an attacker does not need to exploit a code execution vector, only a crafted HTML page delivered remotely. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The likely attack path is social engineering: an attacker hosts a malicious webpage that displays spoofed menu items when a user visits the site, leading them to perform unintended actions.

Generated by OpenCVE AI on September 29, 2026 at 23:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 154.0.8037.57 or later.
  • If an upgrade is not possible, disable all extensions from untrusted sites by setting the browser to request permission only.
  • Educate users to verify that any extension prompts or menu options appear legitimate and to remain skeptical of unexpected requests.

Generated by OpenCVE AI on September 29, 2026 at 23:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Wed, 30 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Extensions Menu in Google Chrome

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in ExtensionsMenu in Google Chrome prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T18:40:58.140Z

Reserved: 2026-09-22T05:08:12.645Z

Link: CVE-2026-95307

cve-icon Vulnrichment

Updated: 2026-09-29T18:40:21.341Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:22.763

Modified: 2026-09-29T19:17:30.597

Link: CVE-2026-95307

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T00:00:13Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information