Executive brief
Google Chrome's download feature displays misleading UI information that can trick users into bypassing system access restrictions. An attacker can craft a malicious HTML page that, when visited, exploits this visual deception through social engineering to circumvent security protections that normally prevent unauthorized access.
Technical details
This vulnerability is a UI misrepresentation (misleading UI rendering) in Chrome's download handling mechanism. The vulnerability allows a remote attacker to craft a malicious HTML page that, when visited by a user, presents false visual information in the download interface. By leveraging social engineering tactics, an attacker can trick users into taking actions that bypass system access restrictions. The attack requires user interaction (visiting a crafted page and responding to the misleading UI). The vulnerability was fixed in Chrome version 153.0.8010.36 and later versions.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-09: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36