Executive brief
Google Chrome's geometry rendering component contains a UI misrepresentation flaw that allows attackers to spoof browser interface elements through a crafted webpage. An attacker could leverage social engineering—for example, by creating a fake login prompt or security warning—to trick users into revealing sensitive information or performing unwanted actions, potentially compromising user accounts or data.
Technical details
This is a UI misrepresentation vulnerability (CWE-451) in Chrome's Geometry component that allows spoofing of UI elements. The vulnerability is triggered via a crafted HTML page and requires social engineering to exploit—the attacker must convince a user to interact with the spoofed UI. The attack vector is network-based and does not require authentication. A successful exploit enables visual deception of the user interface, potentially leading to credential theft or unauthorized actions. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released