Junglewise Threat Intelligence

CVE-2026-87501: Google Chrome UI misrepresentation in password manager

CVE-2026-87501 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's password manager could display misleading UI elements, allowing attackers to trick users into thinking they are interacting with legitimate password prompts when viewing a malicious web page. An attacker could use this to spoof Chrome's security UI and deceive users into revealing sensitive information or taking unintended actions, potentially compromising account credentials.

Technical details

This vulnerability is a UI misrepresentation issue in Google Chrome's password manager component, classified as a spoofing vulnerability (CWE-451). The attack is triggered by a crafted HTML page delivered over the network, requiring user interaction to view the malicious content. The vulnerability allows a remote, unauthenticated attacker to display fake or misleading password prompts that visually resemble legitimate Chrome security UI, potentially deceiving users into revealing credentials or authorizing unwanted actions. The vulnerability was patched in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats