Spoofing attack in Google Chromium - CVE-2026-87462
Published: September 9, 2026
Vulnerability details
The vulnerability allows a remote attacker to misrepresent FedCM user interface elements.
The vulnerability exists due to UI misrepresentation in FedCM when rendering FedCM user interface elements. A remote attacker can induce a victim to interact with misleading FedCM user interface elements to misrepresent FedCM user interface elements.
User interaction is required.
Affected software
Google Chrome
How to mitigate CVE-2026-87462
Google Chrome - update to 153.0.8010.36