Executive brief
Google Chrome's rendering engine contains an input validation flaw that allows attackers who have already compromised the renderer process to spoof user interface elements, deceiving users about the legitimacy of pages or actions. While this requires a prior renderer compromise, successful exploitation could enable phishing, credential theft, or other social engineering attacks that appear to come from trusted browser UI.
Technical details
A improper input validation vulnerability in Chromium's renderer process allows crafted network traffic to bypass validation checks and spoof browser UI elements. The vulnerability is reachable only by attackers who have already achieved code execution within the renderer process (a high-barrier precondition). Exploitation enables UI spoofing via crafted network messages, which could be leveraged for social engineering attacks. The vulnerability was patched in Chrome 153.0.8010.36 and later versions, released in September 2026. No evidence of in-the-wild exploitation exists at the time of advisory publication.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed: CVE-2026-87568 published on NVD
- 2026-09-08: patched: Chrome 153.0.8010.36 released with fix