Junglewise Threat Intelligence

CVE-2026-8564: Google Chrome UI spoofing in Downloads

CVE-2026-8564 · Severity: medium · CVSS 4.2 · Published 2026-05-14

Technologies: Apple macOS, Google Chrome, Google Android. Vendors: Apple, Google.

Executive brief

A security flaw in Google Chrome for Android and Mac could allow a malicious website to misrepresent security information in the browser's download interface. By tricking a user into visiting a specially crafted webpage, an attacker could spoof the user interface to hide warnings or provide false information about a file being downloaded. This could lead users to inadvertently download and open malicious files they would otherwise have avoided.

Technical details

A UI spoofing vulnerability exists in the Downloads component of Google Chrome for Android and Mac. The flaw stems from an incorrect security UI implementation that can be manipulated by a remote attacker using a crafted HTML page. By leveraging this vulnerability, an attacker can present misleading security information or hide legitimate warnings during the file download process. Exploitation requires a user to visit a malicious website (User Interaction). The issue is resolved in version 148.0.7778.168.

Affected products

  • Google Chrome prior to 148.0.7778.168

Timeline

  • 2025-05-16: disclosed: Reported by Alesandro Ortiz
  • 2026-05-12: patched: Fixed in Stable Channel Update 148.0.7778.168
  • 2026-05-14: advisory: NVD publication date

References

Related threats