Junglewise Threat Intelligence

CVE-2026-87445: Google Chrome UI spoofing in Session via crafted HTML

CVE-2026-87445 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Session component fails to properly represent UI elements, allowing a remote attacker to deceive users by spoofing browser interface elements through a specially crafted web page. An attacker could use this to trick users into believing they are interacting with legitimate browser UI, potentially leading to credential theft, phishing attacks, or malware installation.

Technical details

The vulnerability is a UI misrepresentation issue in Chrome's Session component that allows spoofing of browser UI elements. The root cause lies in improper validation or rendering of HTML content, enabling an attacker to craft a malicious HTML page that visually mimics legitimate browser interface elements. Attack requires user interaction (visiting a crafted web page) but does not require authentication or special network positioning. An attacker can deceive users into interacting with fake UI elements, facilitating phishing, credential capture, or social engineering attacks. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats