Executive brief
Google Chrome's download feature contained a clickjacking vulnerability that allowed attackers to trick users into performing unintended actions through spoofed UI elements on a malicious webpage. By using social engineering tactics and crafted HTML pages, an attacker could deceive users into downloading or executing harmful files, potentially leading to malware infection or data compromise.
Technical details
This is a clickjacking/UI spoofing vulnerability in the Chrome download interface. The vulnerability allows a remote attacker to overlay or manipulate UI elements via a crafted HTML page, deceiving users into clicking on elements they believe are legitimate browser controls. The attack requires user interaction (visiting a malicious site and clicking) but no authentication. Successful exploitation could lead to unwanted downloads or execution of malicious files. The vulnerability was patched in Chrome version 153.0.8010.36 released on September 8, 2026.
Affected products
- Google Chrome prior to 153.0.8010.36
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched: Fixed in Chrome 153.0.8010.36