Junglewise Threat Intelligence

CVE-2026-87484: Google Chrome UI spoofing in Geometry rendering

CVE-2026-87484 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's geometry rendering component contains a UI misrepresentation flaw that allows attackers to spoof browser interface elements through a crafted webpage. An attacker could leverage social engineering—for example, by creating a fake login prompt or security warning—to trick users into revealing sensitive information or performing unwanted actions, potentially compromising user accounts or data.

Technical details

This is a UI misrepresentation vulnerability (CWE-451) in Chrome's Geometry component that allows spoofing of UI elements. The vulnerability is triggered via a crafted HTML page and requires social engineering to exploit—the attacker must convince a user to interact with the spoofed UI. The attack vector is network-based and does not require authentication. A successful exploit enables visual deception of the user interface, potentially leading to credential theft or unauthorized actions. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats