CVE-2026-87496
PoC massUI Spoofing in Google Chrome Prior to 153.0.8010.36
Google Chrome contains a Medium-severity user interface misrepresentation flaw (CWE-451) in its Browser component that affects all releases prior to 153.0.8010.36. A remote attacker triggers it by using social engineering to convince a user to open a crafted HTML page, which then spoofs UI elements so that the browser misrepresents critical information to the user. The impact is deception rather than code execution, meaning spoofed UI can lend credibility to phishing and credential-theft pages, and the CVSS 5.4 score reflects low confidentiality and availability impact with user interaction required. All Google Chrome users running builds older than 153.0.8010.36 are affected. Exploitation is currently low: the flaw is not in CISA's KEV catalog, EPSS assigns a 0.2% probability of exploitation within 30 days (11th percentile), and only one public reference (the Chromium issue tracker entry) is known, indicating a proof of concept rather than observed in-the-wild attacks.
What to do: Update Google Chrome to 153.0.8010.36 or later; verify the build via Settings > About Chrome (which also forces the update) or push the fixed build through enterprise endpoint-management tooling. Until patched, treat links from untrusted sources with caution and be suspicious of unexpected browser dialogs or prompts, since successful spoofing depends on user interaction via social engineering.
| google chrome | < 153.0.8010.36 (all builds prior; fixed in 153.0.8010.36) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
UI misrepresentation in Browser in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-451
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.