CVE-2026-87599
PoC massUI Spoofing via Improper Input Validation in Google Chrome Interstitials
Google Chrome versions prior to 153.0.8010.36 contain an improper input validation flaw (CWE-20) in the browser's interstitials — the full-screen pages Chrome displays for certificate errors and safe-browsing warnings. A remote attacker can trigger the issue by persuading a user to open a crafted HTML page, allowing attacker-controlled content to spoof or misrepresent browser UI elements on screen. The practical gain is deception of the user, typically as an aid to phishing or clickjacking; the CVSS 5.4 score reflects limited confidentiality and availability impact with user interaction required. All users running Chrome builds older than 153.0.8010.36 are affected, and Chromium rates the flaw Medium severity. There are no reports of in-the-wild exploitation: one public proof-of-concept is tracked on the Chromium issue tracker, the flaw is not in CISA's KEV, and EPSS assigns a 0.2% probability of exploitation in the next 30 days.
What to do: Update Chrome to 153.0.8010.36 or later, verifying via chrome://settings/help on unmanaged devices; auto-update will remediate most installs. Enterprises should audit fleet browser versions through their update management tooling and prioritize hosts whose users browse untrusted sites. Until patched, users should treat on-screen warnings and prompts appearing over interstitial pages from untrusted sites with added skepticism.
| google chrome | All versions prior to 153.0.8010.36 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper input validation in Interstitials in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
- Vendors
- Products
- chrome
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
In the news0 stories
No ingested article mentions this CVE yet.