Executive brief
Google Chrome is a web browser used by millions of users worldwide to access websites and web applications. This vulnerability allows an attacker who has already compromised a webpage's rendering engine to forge or spoof browser UI elements, potentially tricking users into performing unintended actions such as clicking malicious links or granting permissions they didn't authorize. An exploit requires pre-existing renderer process compromise, limiting immediate risk but affecting the integrity of what users see on their screen.
Technical details
A missing authorization check in Google Chrome's Browser component allows spoofing of UI elements through a crafted HTML page, but only after the renderer process has been compromised by an attacker. The vulnerability is classified as an authorization bypass affecting the trusted UI surface. Attack preconditions include prior compromise of the renderer process (e.g., via a separate browser vulnerability or malicious script injection). An attacker can craft HTML that causes the browser to display fake UI elements or dialogs, misleading users into unintended actions. The fix is available in Chrome version 153.0.8010.47 and later.
Affected products
- Google Chrome prior to 153.0.8010.47
Timeline
- 2026-09-15: disclosed
- 2026-09-15: patched: Fixed in version 153.0.8010.47