Junglewise Threat Intelligence

CVE-2026-87559: Google Chrome UI spoofing via crafted HTML

CVE-2026-87559 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a UI misrepresentation vulnerability that allows attackers to spoof user interface elements through a crafted HTML page. An attacker could use social engineering to trick users into believing they are interacting with legitimate Chrome UI, potentially leading to phishing attacks or credential theft.

Technical details

This is a UI misrepresentation vulnerability in Google Chrome's user interface handling. A remote attacker can craft a malicious HTML page that spoofs legitimate Chrome UI elements, requiring only that a user visits the page. The vulnerability affects Chrome versions prior to 153.0.8010.36. Exploitation requires social engineering but can be delivered via network access. Google has patched this issue in Chrome 153.0.8010.36 and later versions.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed: CVE-2026-87559 published
  • 2026-09-08: patched: Chrome 153.0.8010.36 released with fix

References

Related threats