Spoofing attack in Google Chromium - CVE-2026-87484

 

Spoofing attack in Google Chromium - CVE-2026-87484

Published: September 9, 2026


Vulnerability identifier: #VU148625
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-87484
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to spoof user interface elements.

The vulnerability exists due to UI misrepresentation in Geometry when rendering crafted web content. A remote attacker can cause crafted web content to be rendered to spoof user interface elements.

User interaction is required to view the crafted web content.


Affected software

Google Chromium
Google Chrome

How to mitigate CVE-2026-87484

Install security update from vendor's website.

Google Chromium - update to 153.0.8010.36
Google Chrome - update to 153.0.8010.36

External References

Related Security Bulletins