Junglewise Threat Intelligence

CVE-2026-87567: Google Chrome UI misrepresentation in URL formatting

CVE-2026-87567 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's URL formatting component contains a flaw that allows attackers to trick users into visiting malicious websites by disguising the actual domain in the address bar. By using carefully crafted domain names combined with social engineering, an attacker can spoof the browser's address bar, making it appear as though the user is visiting a legitimate site when they are actually on an attacker-controlled domain. This could lead to credential theft, account takeover, or malware infection if users are deceived into performing actions they believe are on trusted sites.

Technical details

This is a UI misrepresentation vulnerability in Chrome's UrlFormatting component that allows domain spoofing attacks. An attacker can craft a malicious domain name that, when rendered in Chrome's address bar, appears to represent a different (legitimate) domain due to improper formatting or display logic. The attack requires user interaction—specifically social engineering to trick the user into clicking a link to the malicious domain—but does not require authentication or special network positioning. Successful exploitation allows the attacker to visually deceive users into believing they are on a trusted website while actually viewing attacker-controlled content. The vulnerability was patched in Chrome 153.0.8010.36, released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched

References

Related threats