CVE-2026-87484
PoC massUI Spoofing in Google Chrome via Crafted HTML Pages
CVE-2026-87484 is a user interface misrepresentation (spoofing) flaw in the Geometry component of Google Chrome, classified under CWE-451. A remote attacker must lure a user to a specially crafted HTML page and combine the flaw with social engineering to misrepresent browser UI elements. If successful, the attacker can make malicious page content appear to be trusted browser interface elements, potentially deceiving users into revealing information or taking actions they otherwise would not. Anyone running an affected version of Chrome prior to 153.0.8010.36 is exposed, though user interaction is required for exploitation. There is no evidence of in-the-wild exploitation; a public proof-of-concept reference exists in the Chromium issue tracker and CISA has not added it to the KEV catalog.
What to do: Update Chrome to 153.0.8010.36 or later, which resolves this flaw; verify the version via Settings > About Chrome, as auto-update may need a browser relaunch to complete. Until patched, exercise caution on untrusted pages and scrutinize unexpected UI prompts or dialogs, since this spoofing flaw relies on social engineering. Confirm that managed endpoints and kiosk/browser-only deployments have also received the updated build.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
UI misrepresentation in Geometry in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-451
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.