ZeroHour

CVE-2026-87599

PoC mass

UI Spoofing via Improper Input Validation in Google Chrome Interstitials

CVSS 3.1
5.4 medium
EPSS
<1%p8
Published
()
Modified
AI analysis

Google Chrome versions prior to 153.0.8010.36 contain an improper input validation flaw (CWE-20) in the browser's interstitials — the full-screen pages Chrome displays for certificate errors and safe-browsing warnings. A remote attacker can trigger the issue by persuading a user to open a crafted HTML page, allowing attacker-controlled content to spoof or misrepresent browser UI elements on screen. The practical gain is deception of the user, typically as an aid to phishing or clickjacking; the CVSS 5.4 score reflects limited confidentiality and availability impact with user interaction required. All users running Chrome builds older than 153.0.8010.36 are affected, and Chromium rates the flaw Medium severity. There are no reports of in-the-wild exploitation: one public proof-of-concept is tracked on the Chromium issue tracker, the flaw is not in CISA's KEV, and EPSS assigns a 0.2% probability of exploitation in the next 30 days.

What to do: Update Chrome to 153.0.8010.36 or later, verifying via chrome://settings/help on unmanaged devices; auto-update will remediate most installs. Enterprises should audit fleet browser versions through their update management tooling and prioritize hosts whose users browse untrusted sites. Until patched, users should treat on-screen warnings and prompts appearing over interstitial pages from untrusted sites with added skepticism.

Affected
google chromeAll versions prior to 153.0.8010.36
Estimated exposure
masshundreds of millions of users (Chrome's global user base exceeds 3 billion, and pre-153.0.8010.36 builds were widespread at disclosure before auto-update… — Chrome is the world's most-used browser with a publicly reported user base above 3 billion, and although auto-update remediates most installs within days, the population on older builds at any given time is reliably in the hundreds of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)

Vendors
google
Products
chrome
Weakness
CWE-20
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

No ingested article mentions this CVE yet.