ZeroHour

CVE-2026-93386

mass

UI Misrepresentation (Spoofing) in Google Chrome WebAppInstalls

CVSS 3.1
5.4 medium
EPSS
Published
()
Modified
AI analysis

CVE-2026-93386 is a UI misrepresentation flaw (CWE-451) in the WebAppInstalls component of Google Chrome, allowing a remote attacker to spoof UI elements through a specially crafted HTML page. The attack is triggered via social engineering: a user must be lured into opening the crafted page, which then presents misleading interface elements, such as a deceptive web-app install prompt or dialog content. Successful spoofing could make fake prompts or dialogs appear trustworthy, tricking users into actions or beliefs that aid a phishing-style deception. All users running Google Chrome versions prior to 153.0.8010.52 are affected, and the flaw was rated Low severity by Chromium maintainers. There is no evidence of exploitation in the wild, no public proof-of-concept, and the issue is not listed in CISA's KEV catalog; it was patched in the Chrome 153.0.8010.52 release, which fixed 16 security issues.

What to do: Update Google Chrome to version 153.0.8010.52 or later on all desktop platforms (check chrome://settings/help and restart the browser to confirm the update is applied), since Chrome normally auto-updates but may need a restart. As an interim mitigation, treat unexpected web-app install prompts with suspicion and avoid granting install or permission requests from untrusted pages. Monitor the dashboard for any addition to CISA KEV or emergence of a public proof-of-concept.

Affected
Google Chromeall versions prior to 153.0.8010.52
Estimated exposure
mass≈3 billion Chrome users (Chrome holds roughly 65% of global browser usage; all pre-153.0.8010.52 installs affected) — Estimated from Chrome's dominant global browser market share and Google's publicly reported multi-billion-user install base, since every Chrome version before 153.0.8010.52 contains the flaw.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0.8010.52 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)

Weakness
CWE-451
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

In the news

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.