Executive brief
Google Chrome contains an incorrect authorization vulnerability in its Isolated component that allows remote attackers to spoof UI elements by sending a crafted HTML page. This could trick users into interacting with fake browser interface elements, potentially leading to credential theft, malware installation, or other attacks that exploit user trust in the browser UI.
Technical details
The vulnerability exists in Chrome's Isolated component due to incorrect authorization checks. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that tricks the browser into displaying spoofed UI elements. The attack does not require user authentication or special privileges; visiting a malicious webpage is sufficient. Successful exploitation allows the attacker to create convincing fake browser UI components (such as address bar, warning dialogs, or permission prompts), which could be used in social engineering attacks. The vulnerability was fixed in Chrome version 153.0.8010.36 and later.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released