Executive brief
Google Chrome on macOS is vulnerable to UI spoofing attacks through its Accessibility feature. An attacker can craft a malicious web page that tricks users into interacting with fake interface elements, potentially leading to credential theft, unauthorized actions, or other user deception. This affects Chrome versions before 153.0.8010.36 on Mac.
Technical details
The vulnerability is an incorrect reference resolution flaw in Chrome's Accessibility component on macOS that allows UI element spoofing. The vulnerability is triggered when a user visits a crafted HTML page, requiring no authentication or special privileges. An attacker can exploit this to spoof UI elements, potentially deceiving users into interacting with malicious content. The issue is resolved in Chrome version 153.0.8010.36 and later for macOS.
Affected products
- Google Chrome prior to 153.0.8010.36 on macOS
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Chrome 153.0.8010.36 released