Junglewise Threat Intelligence

CVE-2026-87599: Google Chrome improper input validation in Interstitials

CVE-2026-87599 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in how it validates user input in interstitial pages (warning or confirmation dialogs shown to users). An attacker can create a malicious web page that tricks Chrome's safety dialogs into displaying fake UI elements, such as fake warning messages or redirect buttons. This could lead users to click through security warnings they shouldn't trust or interact with spoofed interface elements.

Technical details

The vulnerability is an improper input validation flaw in Chrome's Interstitials component. The issue allows a remote attacker to spoof UI elements by crafting a malicious HTML page that bypasses Chrome's validation checks. The attack requires the attacker to host a crafted HTML page and lure a user to visit it, with no additional authentication or special privileges needed. An exploit could display fake browser UI, fake warning dialogs, or misleading interface elements that trick users into taking unintended actions. The vulnerability is fixed in Chrome 153.0.8010.36 and later.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats