ZeroHour

CVE-2026-87501

PoC mass

UI Spoofing (CWE-451) in Google Chrome Passwords Feature

CVSS 3.1
5.4 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-87501 is a UI misrepresentation flaw in the Passwords feature of Google Chrome that allows a remote attacker to spoof UI elements through a crafted HTML page. It is triggered when a user visits or loads attacker-controlled HTML content, causing password-related interface elements to be misrepresented. An attacker gains the ability to make dialogs or prompts in the Passwords UI appear untrustworthy or misleading, potentially tricking users into unintended actions; the CVSS impact is low for confidentiality and availability with no direct integrity impact. Any user running Google Chrome prior to 153.0.8010.36 is affected until they update. There is no evidence of in-the-wild exploitation so far; one public proof-of-concept reference exists on the Chromium issue tracker, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.

What to do: Update Google Chrome to version 153.0.8010.36 or later (available via Settings > About Chrome or your enterprise update channel), and verify managed fleets are reporting patched builds. Until updated, treat unexpected password-save or password-manager prompts with caution, especially on unfamiliar pages. Track the referenced Chromium issue (513509804) for any further technical details or exploitation reports.

Affected
Google Chromeprior to 153.0.8010.36
Estimated exposure
mass≈3+ billion users (Chrome's global install base on pre-153.0.8010.36 builds) — Chrome is the world's most widely used desktop browser with an install base in the billions, and every user on versions before 153.0.8010.36 is affected until patched.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.