Executive brief
Google Chrome's fullscreen feature in versions prior to 153.0.8010.36 contains a flaw that allows attackers with access to the browser's renderer process to deceive users into believing they are interacting with legitimate UI elements. Combined with social engineering, this vulnerability could lead to phishing attacks or credential theft without requiring direct exploitation of the browser itself.
Technical details
The vulnerability is a confused deputy attack in Chrome's fullscreen implementation that allows spoofing of UI elements. An attacker who has compromised the renderer process can leverage this flaw along with social engineering to display crafted HTML that mimics legitimate browser UI, misleading users about the security or authenticity of content. The attack requires both renderer process compromise and user interaction via a crafted HTML page. The issue has been patched in Chrome 153.0.8010.36 and later versions, released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel