Executive brief
Google Chrome contains a flaw in its browser interface rendering that allows attackers to spoof or misrepresent UI elements to users through specially crafted web pages. An attacker could trick users into believing they are interacting with legitimate interface elements when they are actually looking at spoofed content, potentially leading to credential theft, malware installation, or other social engineering attacks.
Technical details
This vulnerability is a UI misrepresentation issue in Chrome's browser engine where crafted HTML pages can deceive the rendering of browser UI elements. The attack requires social engineering to trick a user into visiting a malicious page, and leverages the browser's rendering logic to display fake or spoofed UI components. The vulnerability affects Chrome versions prior to 153.0.8010.36. Attackers can craft HTML pages that visually mislead users about the legitimacy or source of content or interface elements. The fix is available in Chrome 153.0.8010.36 and later for Windows, macOS, and Linux platforms.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87496 disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released with fix