ZeroHour

CVE-2026-87540

PoC mass

UI Spoofing via Incorrect Authorization in Google Chrome Prior to 153.0.8010.36

CVSS 3.1
5.4 medium
EPSS
<1%p7
Published
()
Modified
AI analysis

CVE-2026-87540 is an incorrect authorization flaw (CWE-863) in the Isolated component of Google Chrome that lets a remote attacker spoof UI elements. Triggering it requires luring a user to open a crafted HTML page, which is reflected in the CVSS 3.1 user-interaction requirement. If successful, the attacker can present misleading browser or page UI, which is typically leveraged for phishing or deceiving users about what they are interacting with. All Chrome users running versions before 153.0.8010.36 are affected. Exploitation has not been observed in the wild (not in CISA KEV, EPSS is 0.2%), but one public proof-of-concept reference exists in the Chromium issue tracker.

What to do: Update Google Chrome to version 153.0.8010.36 or later; users can verify their current version at chrome://settings/help and relaunch after the update applies. Enterprise administrators should push the updated build through their patch-management channel. As an interim mitigation, exercise caution when opening HTML pages from untrusted sources.

Affected
google chromeall versions prior to 153.0.8010.36
Estimated exposure
masson the order of billions of Chrome users potentially affected until they update (Chrome has a multi-billion global install base) — Chrome's worldwide installed base is estimated at over 3 billion users based on public browser market-share data, and the flaw affects all builds prior to 153.0.8010.36, so exposure is bounded only by how quickly users update.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-863
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.