CVE-2026-87445
PoC massUI Spoofing Flaw in Google Chrome Session Component (Prior to 153.0.8010.36)
CVE-2026-87445 is a UI misrepresentation (spoofing) vulnerability in the Session component of Google Chrome, tracked as CWE-451, with a Chromium security severity of Medium. An attacker triggers it by luring a user to a crafted HTML page, where browser UI elements can be misrepresented to the user. Successful spoofing can deceive users into trusting attacker-controlled UI, potentially enabling phishing-style deception, with the CVSS vector indicating low confidentiality and low availability impact and no privilege requirements beyond user interaction. Users of Google Chrome prior to version 153.0.8010.36 are affected. Exploitation has not been reported in the wild and the flaw is not in CISA KEV; a public proof-of-concept reference exists in the Chromium issue tracker, and EPSS estimates only a 0.3% probability of exploitation within 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later, which is available via the browser's built-in auto-update mechanism; verify the installed version at chrome://settings/help and force a check for updates where auto-update is disabled. No workaround is specified, so until patching, users should treat unexpected or unfamiliar browser UI prompts and dialogs on untrusted sites with suspicion.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-451
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.