CVE-2026-91739: Google Chrome vulnerability
Published Sep 15, 2026
·Updated
Missing authorization in Transactions Platform in Google Chrome prior to 153.0.8010.47 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Affected Software
1 affected component
Google Chrome<153.0.8010.47
Event History
Sep 15, 2026
CVE Published
via MITRE·08:41 PM
Data Sourced
via MITRE·08:41 PM
DescriptionWeakness
Frequently Asked Questions
1
What must an attacker achieve before this issue can be exploited?
The attacker must first compromise the Chrome renderer process. The spoofing issue is then triggered using a crafted HTML page.
2
Which Chrome versions should be remediated?
Google Chrome versions prior to 153.0.8010.47 are affected. Update Chrome to 153.0.8010.47 or later.
3
What is the practical impact after exploitation?
An attacker who has compromised the renderer can spoof UI elements, which could make malicious content appear to be legitimate browser or site interface elements.