CVE-2026-87472: Input Validation
Published Sep 9, 2026
·Updated
Improper input validation in FedCM in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Chrome<153.0.8010.36
Event History
Sep 9, 2026
CVE Published
via MITRE·12:09 AM
Data Sourced
via MITRE·12:09 AM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker achieve before this issue can be exploited?
The attacker must already have compromised the Chrome renderer process. They can then use a crafted HTML page to spoof UI elements.
2
Which Chrome versions need to be updated?
Google Chrome versions prior to 153.0.8010.36 are affected. Update Chrome to 153.0.8010.36 or a later version.
3
Is this exploitable by a remote attacker without any prior foothold?
The provided information describes remote exploitation only after the renderer process has been compromised. It does not state that this flaw alone provides initial renderer-process compromise.