CVE-2026-87501
PoC massUI Spoofing (CWE-451) in Google Chrome Passwords Feature
CVE-2026-87501 is a UI misrepresentation flaw in the Passwords feature of Google Chrome that allows a remote attacker to spoof UI elements through a crafted HTML page. It is triggered when a user visits or loads attacker-controlled HTML content, causing password-related interface elements to be misrepresented. An attacker gains the ability to make dialogs or prompts in the Passwords UI appear untrustworthy or misleading, potentially tricking users into unintended actions; the CVSS impact is low for confidentiality and availability with no direct integrity impact. Any user running Google Chrome prior to 153.0.8010.36 is affected until they update. There is no evidence of in-the-wild exploitation so far; one public proof-of-concept reference exists on the Chromium issue tracker, and EPSS estimates only about a 0.2% probability of exploitation in the next 30 days.
What to do: Update Google Chrome to version 153.0.8010.36 or later (available via Settings > About Chrome or your enterprise update channel), and verify managed fleets are reporting patched builds. Until updated, treat unexpected password-save or password-manager prompts with caution, especially on unfamiliar pages. Track the referenced Chromium issue (513509804) for any further technical details or exploitation reports.
| Google Chrome | prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
UI misrepresentation in Passwords in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-451
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.