Junglewise Threat Intelligence

CVE-2026-87623: Google Chrome Observable discrepancy in DOM

CVE-2026-87623 · Severity: medium · CVSS 6.5 · Published 2026-09-09

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by millions to access websites and online services. This vulnerability allows an attacker to create a deceptive webpage that tricks users into revealing sensitive information by exploiting visual inconsistencies in how Chrome displays content. The attack requires social engineering (user interaction with a malicious link) and could lead to credential theft or personal data exposure.

Technical details

This is a DOM (Document Object Model) discrepancy vulnerability in Google Chrome that enables phishing and information disclosure attacks. The root cause is an inconsistency in how the browser renders or displays DOM elements, which can be exploited by an attacker crafting a malicious HTML page to create a visually misleading interface. The attack vector is network-based and requires social engineering to trick a user into visiting a crafted webpage; no authentication or special privileges are required from the attacker. An attacker can leverage this discrepancy to harvest sensitive information such as credentials or personal data. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36

References

Related threats