CVE-2026-87540
PoC massUI Spoofing via Incorrect Authorization in Google Chrome Prior to 153.0.8010.36
CVE-2026-87540 is an incorrect authorization flaw (CWE-863) in the Isolated component of Google Chrome that lets a remote attacker spoof UI elements. Triggering it requires luring a user to open a crafted HTML page, which is reflected in the CVSS 3.1 user-interaction requirement. If successful, the attacker can present misleading browser or page UI, which is typically leveraged for phishing or deceiving users about what they are interacting with. All Chrome users running versions before 153.0.8010.36 are affected. Exploitation has not been observed in the wild (not in CISA KEV, EPSS is 0.2%), but one public proof-of-concept reference exists in the Chromium issue tracker.
What to do: Update Google Chrome to version 153.0.8010.36 or later; users can verify their current version at chrome://settings/help and relaunch after the update applies. Enterprise administrators should push the updated build through their patch-management channel. As an interim mitigation, exercise caution when opening HTML pages from untrusted sources.
| google chrome | all versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Incorrect authorization in Isolated in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-863
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.