ZeroHour

CVE-2026-87445

PoC mass

UI Spoofing Flaw in Google Chrome Session Component (Prior to 153.0.8010.36)

CVSS 3.1
5.4 medium
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2026-87445 is a UI misrepresentation (spoofing) vulnerability in the Session component of Google Chrome, tracked as CWE-451, with a Chromium security severity of Medium. An attacker triggers it by luring a user to a crafted HTML page, where browser UI elements can be misrepresented to the user. Successful spoofing can deceive users into trusting attacker-controlled UI, potentially enabling phishing-style deception, with the CVSS vector indicating low confidentiality and low availability impact and no privilege requirements beyond user interaction. Users of Google Chrome prior to version 153.0.8010.36 are affected. Exploitation has not been reported in the wild and the flaw is not in CISA KEV; a public proof-of-concept reference exists in the Chromium issue tracker, and EPSS estimates only a 0.3% probability of exploitation within 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later, which is available via the browser's built-in auto-update mechanism; verify the installed version at chrome://settings/help and force a check for updates where auto-update is disabled. No workaround is specified, so until patching, users should treat unexpected or unfamiliar browser UI prompts and dialogs on untrusted sites with suspicion.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
massbillions of Chrome users/installations (Chrome is the dominant browser by market share, roughly two-thirds of desktop usage) — Chrome's leading desktop browser market share (~65%+) implies an installed base on the order of billions, all of which remain exposed until updated to 153.0.8010.36 or later.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UI misrepresentation in Session in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.