Junglewise Threat Intelligence

CVE-2026-87507: Google Chrome UI misrepresentation in Downloads

CVE-2026-87507 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Downloads feature contains a UI misrepresentation vulnerability that allows attackers to spoof the download interface through carefully crafted HTML pages. An attacker could use social engineering to trick users into believing they are downloading legitimate files, potentially leading to malware installation or credential theft.

Technical details

This vulnerability is a UI spoofing/misrepresentation flaw in Chrome's Downloads component that allows remote attackers to craft HTML pages that deceive users about the nature or origin of downloads. The attack requires social engineering (user interaction) to be effective and leverages the attacker's ability to control rendered HTML content. The vulnerability affects Chrome versions prior to 153.0.8010.36. The fix is available in Chrome 153.0.8010.36 and later versions across Windows, Mac, and Linux platforms.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released to stable channel

References

Related threats