ZeroHour

CVE-2026-87484

PoC mass

UI Spoofing in Google Chrome via Crafted HTML Pages

CVSS 3.1
5.4 medium
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-87484 is a user interface misrepresentation (spoofing) flaw in the Geometry component of Google Chrome, classified under CWE-451. A remote attacker must lure a user to a specially crafted HTML page and combine the flaw with social engineering to misrepresent browser UI elements. If successful, the attacker can make malicious page content appear to be trusted browser interface elements, potentially deceiving users into revealing information or taking actions they otherwise would not. Anyone running an affected version of Chrome prior to 153.0.8010.36 is exposed, though user interaction is required for exploitation. There is no evidence of in-the-wild exploitation; a public proof-of-concept reference exists in the Chromium issue tracker and CISA has not added it to the KEV catalog.

What to do: Update Chrome to 153.0.8010.36 or later, which resolves this flaw; verify the version via Settings > About Chrome, as auto-update may need a browser relaunch to complete. Until patched, exercise caution on untrusted pages and scrutinize unexpected UI prompts or dialogs, since this spoofing flaw relies on social engineering. Confirm that managed endpoints and kiosk/browser-only deployments have also received the updated build.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
mass≈3 billion users (Chrome's global install base) — Chrome is the world's dominant desktop browser with roughly 65% market share and a multi-billion-user install base, so essentially every Chrome deployment older than 153.0.8010.36 is affected.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.