Executive brief
Google Chrome's Geometry rendering component could misrepresent UI elements on web pages, allowing attackers to create convincing fake login screens or other deceptive interfaces. An attacker would need to trick a user into visiting a specially crafted webpage, potentially leading to credential theft or other social engineering attacks.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's Geometry component that permits spoofing of user interface elements. The vulnerability exists in Google Chrome versions prior to 153.0.8010.36 and can be triggered remotely via a crafted HTML page. The attack requires social engineering to be effective, as the user must visit the malicious page. An attacker can create a fake UI overlay or phishing interface that mimics legitimate browser chrome or website elements, potentially capturing user credentials or sensitive input. The fix is available in Chrome 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched