Junglewise Threat Intelligence

CVE-2026-87653: Google Chrome UI misrepresentation in fullscreen mode

CVE-2026-87653 · Severity: medium · CVSS 5.4 · Published 2026-09-09

Executive brief

Google Chrome's fullscreen display on Windows can be tricked by a malicious webpage into showing fake user interface elements, such as fake dialog boxes or address bar content. This could allow an attacker to deceive users into believing they are interacting with legitimate Chrome controls when they are actually viewing attacker-controlled content, potentially leading to phishing or credential theft.

Technical details

This vulnerability is a UI misrepresentation (spoofing) vulnerability in Chrome's fullscreen implementation on Windows. The root cause exists in Chrome's fullscreen rendering logic, allowing remote attackers to craft a specially designed HTML page that overlays fake UI elements on top of the actual browser chrome. The attack requires no authentication and is triggered simply by a user visiting a malicious webpage. While the Chromium security team rated this as "Low" severity, the reported CVSS score of 5.4 reflects the potential for social engineering attacks. The vulnerability was patched in Chrome 153.0.8010.36 released on September 8, 2026.

Affected products

  • Google Chrome prior to 153.0.8010.36 on Windows

Timeline

  • 2026-09-08: disclosed: Chrome 153.0.8010.36 released with fix
  • 2026-09-08: patched: Fixed in Chrome 153.0.8010.36 and later

References

Related threats