Executive brief
Google Chrome's navigation system contained an authorization flaw that could allow an attacker who has already compromised the browser's rendering process to spoof UI elements and mislead users. This could enable credential theft or malicious redirection by making fake security warnings or address bar content appear legitimate.
Technical details
This vulnerability is an incorrect authorization flaw in Chrome's Navigation component affecting versions prior to 153.0.8010.36. The issue allows a remote attacker who has already compromised the renderer process to spoof UI elements through a crafted HTML page. The attack requires prior compromise of the renderer process (high precondition) but then enables UI spoofing which could deceive end users. The vulnerability is fixed in Chrome 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36