UI Spoofing Vulnerability in Google Chrome Affecting Remote User Interaction
CVE-2026-95305

4.8MEDIUM

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
29 September 2026

What is CVE-2026-95305?

A vulnerability in Google Chrome prior to version 154.0.8037.57 allows remote attackers to exploit UI misrepresentation through crafted network traffic. This could potentially enable attackers to spoof user interface elements, leveraging social engineering tactics to deceive users into taking actions they might not otherwise consider. By manipulating the appearance of the browser, attackers can create misleading scenarios that could lead to unauthorized access or data disclosure.

Affected Version(s)

Chrome 154.0.8037.57

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.