Junglewise Threat Intelligence

CVE-2026-87502: Google Chrome confused deputy in Fullscreen UI spoofing

CVE-2026-87502 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's fullscreen feature in versions prior to 153.0.8010.36 contains a flaw that allows attackers with access to the browser's renderer process to deceive users into believing they are interacting with legitimate UI elements. Combined with social engineering, this vulnerability could lead to phishing attacks or credential theft without requiring direct exploitation of the browser itself.

Technical details

The vulnerability is a confused deputy attack in Chrome's fullscreen implementation that allows spoofing of UI elements. An attacker who has compromised the renderer process can leverage this flaw along with social engineering to display crafted HTML that mimics legitimate browser UI, misleading users about the security or authenticity of content. The attack requires both renderer process compromise and user interaction via a crafted HTML page. The issue has been patched in Chrome 153.0.8010.36 and later versions, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel

References

Related threats