CVE-2026-87568
Modified Modified - Updated After Analysis

Improper Input Validation in Google Chrome UI Spoofing

Vulnerability report for CVE-2026-87568, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Chrome

Description

Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via crafted network traffic. (Chromium security severity: Low)

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
google chrome to 153.0.8010.36 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves improper input validation in Chromium, which is the open-source project behind Google Chrome. A remote attacker who had already compromised the renderer process could exploit this issue to spoof UI elements by sending crafted network traffic. This could trick users into believing false information or taking unintended actions.

Detection Guidance

Detection of this vulnerability requires monitoring for UI spoofing attempts in Chromium-based browsers like Chrome. Check browser logs for renderer process anomalies or network traffic patterns that may indicate crafted input. No specific commands are provided in the CVE details.

Impact Analysis

If exploited, this vulnerability could allow an attacker to deceive you by displaying fake UI elements in your browser. This might lead to phishing attacks, unauthorized actions, or confusion about the legitimacy of web pages or dialogs.

Compliance Impact

This vulnerability involves improper input validation in Chromium, enabling UI spoofing via crafted network traffic. It does not directly impact data confidentiality or integrity but could mislead users into taking unsafe actions. Compliance impact is likely minimal unless user deception leads to data exposure, which would then depend on specific incident details.

Mitigation Strategies

Update Google Chrome to version 153.0.8010.36 or later to address the improper input validation issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87568. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart