CVE-2026-87538: Medium severity Google Google Chrome vulnerability
Chromium CVE-2026-87538: Clickjacking in Input
Other sources
Clickjacking in Input in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process and leveraged social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
— MITRE
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 153.0.4234.32 - Upgrade
Upgrade
Google Chrome / Chromium-based browsersto a version that resolves this vulnerability.Fixed in 153.0.8010.36
Event History
Frequently Asked Questions
What must an attacker do before this issue can be exploited?
The attacker must first compromise the Chrome renderer process and then use social engineering to persuade a user to interact with a crafted HTML page. The issue is not described as exploitable solely by visiting a page.
Which Chrome versions are affected?
Google Chrome versions earlier than 153.0.8010.36 are affected. Updating to 153.0.8010.36 or later addresses the affected version range.
What is the practical impact of successful exploitation?
A successful attacker can spoof UI elements through a crafted HTML page, potentially misleading the user about what they are interacting with.