Description
UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-09-29
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: Remote UI Spoofing
Action: Patch Chrome
AI Analysis

Impact

A remote attacker can craft a malicious HTML page to cause Google Chrome on Android to display incorrectly rendered UI elements within its Messages interface, enabling the attacker to spoof legitimate UI components and potentially deceive users into providing sensitive information or unknowingly interacting with malicious content.

Affected Systems

The flaw affects Google Chrome on Android versions prior to 154.0.8037.57, specifically the Messages component that handles web content. Users running any Android device with Chrome older than that revision are at risk.

Risk and Exploitability

The CVSS base score of 5.4 indicates a medium severity. With no EPSS score available and the vulnerability not listed in CISA KEV, the current exploitation probability appears modest, but the lack of a publicly known exploit does not guarantee absence of risk. Attackers would need to lure a user to a malicious page through social engineering, making user education a relevant countermeasure. Once triggered, the attacker could present spoofed UI elements that mimic legitimate prompts.

Generated by OpenCVE AI on September 29, 2026 at 23:14 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 154.0.8037.57 or later on all Android devices.
  • Enable automatic updates on the device to receive future security patches promptly.
  • Educate users to verify the legitimacy of links and messages before interacting with them.

Generated by OpenCVE AI on September 29, 2026 at 23:14 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6513-1 chromium security update
History

Tue, 29 Sep 2026 23:30:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation in Chrome Messages Allows Remote Spoofing via Crafted Page

Tue, 29 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 29 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 29 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Messages in Google Chrome on on Android prior to 154.0.8037.57 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-29T18:50:59.928Z

Reserved: 2026-09-22T05:09:32.113Z

Link: CVE-2026-95337

cve-icon Vulnrichment

Updated: 2026-09-29T18:45:14.083Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-29T18:17:26.247

Modified: 2026-09-29T19:17:35.000

Link: CVE-2026-95337

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-29T23:15:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information