Junglewise Threat Intelligence

CVE-2026-87624: Google Chrome UI misrepresentation in Passwords on Android

CVE-2026-87624 · Severity: medium · CVSS 4.2 · Published 2026-09-09

Executive brief

Google Chrome on Android contains a flaw that allows attackers with control of the browser's rendering engine to spoof password-related UI elements through a malicious web page. This could deceive users into believing they are interacting with legitimate security prompts or dialogs, potentially leading to unauthorized disclosure of credentials or sensitive information through social engineering.

Technical details

This is a UI spoofing/misrepresentation vulnerability in Chrome's password management interface on Android. The root cause involves insufficient validation of rendering context restrictions, allowing a compromised renderer process to craft HTML that mimics legitimate password UI elements. The attack requires the renderer process to be compromised (a post-exploitation scenario), meaning an attacker must first successfully execute code within the browser's sandboxed renderer through another vulnerability. The impact is limited to UI deception; an attacker cannot directly access passwords but can manipulate what users see. The vulnerability is fixed in Chrome 153.0.8010.36 and later on Android.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Android

Timeline

  • 2026-09-09: disclosed
  • 2026-09-08: patched: Chrome 153.0.8010.36 released

References

Related threats