
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-0901 is an inappropriate implementation vulnerability in the Blink rendering engine of Google Chrome on Android that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by Irvan Kurniawan (sourc7) on 2021-10-04 and publicly disclosed on January 13, 2026, as part of the Chrome 144 stable channel release. Affected versions include Google Chrome prior to 144.0.7559.59 on Android, as well as Microsoft Edge (Chromium-based) prior to the corresponding patched release. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), as assessed by CISA-ADP (Chrome Releases, Microsoft MSRC).
The root cause is an inappropriate implementation in Blink, Chrome's HTML rendering engine, classified as CWE-451 (User Interface Misrepresentation of Critical Information). An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by a victim on an Android device, causes the browser to misrepresent critical UI elements — enabling UI spoofing attacks such as faking address bar content, security indicators, or dialog prompts. Exploitation requires user interaction (e.g., visiting a malicious URL) but no special privileges. The Chromium issue tracker entry (ID 40057499) is access-restricted pending broad user patching (Chrome Releases).
Successful exploitation allows an attacker to spoof browser UI elements on Android, potentially deceiving users into believing they are on a trusted site or interacting with a legitimate security prompt. This primarily affects confidentiality and integrity at a low level — an attacker could trick users into submitting credentials or accepting malicious content under a false UI context. Availability is not impacted, and the scope is unchanged (limited to the browser process), but the social engineering potential of UI spoofing can amplify phishing and credential-harvesting attacks (Chrome Releases).
Google has addressed this vulnerability in Chrome 144.0.7559.59 (Linux) and 144.0.7559.59/60 (Windows/Mac), released January 13, 2026; Android users should update to this version or later via the Google Play Store. Microsoft Edge (Chromium-based) users should apply the corresponding upstream fix referenced in the Microsoft Security Response Center advisory. No configuration-based workaround is available; updating to the patched version is the only recommended remediation. Organizations should ensure Chrome auto-update policies are enabled and verify endpoint compliance using vulnerability scanners (Qualys, Nessus detection IDs are available) (Chrome Releases, Microsoft MSRC).
The Chrome 144 release received coverage from security news outlets including SecurityOnline, CyberSecurityNews, GBHackers, and CIS, primarily noting the batch of 10 security fixes including CVE-2026-0901. The CIS published an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution (referring to the broader release). Community reaction has been moderate given the Medium CVSS score and Android-specific scope. No notable individual researcher commentary beyond the original reporter (Irvan Kurniawan / sourc7) has been identified (CIS Advisory, Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."