Junglewise Threat Intelligence

CVE-2026-87462: Google Chrome UI misrepresentation in FedCM

CVE-2026-87462 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Federated Credential Management (FedCM) feature contains a UI spoofing vulnerability that allows attackers to deceive users through social engineering tactics. By crafting a malicious HTML page, an attacker can misrepresent login UI elements to trick users into providing credentials or sensitive information. This affects Chrome versions prior to 153.0.8010.36 and could lead to account compromise or credential theft.

Technical details

This vulnerability is a UI misrepresentation flaw in Chrome's Federated Credential Management (FedCM) system. The root cause lies in improper validation of UI elements rendered during the federated login flow, allowing a crafted HTML page to spoof authentication dialogs. An attacker must leverage social engineering to trick a user into visiting a malicious website; the attack requires user interaction but no authentication on the attacker's side. Successful exploitation enables credential theft or account takeover by presenting fake login prompts to users. The vulnerability is patched in Chrome version 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats