CVE-2026-0901
vulnerability analysis and mitigation

Overview

CVE-2026-0901 is an inappropriate implementation vulnerability in the Blink rendering engine of Google Chrome on Android that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by Irvan Kurniawan (sourc7) on 2021-10-04 and publicly disclosed on January 13, 2026, as part of the Chrome 144 stable channel release. Affected versions include Google Chrome prior to 144.0.7559.59 on Android, as well as Microsoft Edge (Chromium-based) prior to the corresponding patched release. The vulnerability carries a CVSS v3.1 base score of 5.4 (Medium), as assessed by CISA-ADP (Chrome Releases, Microsoft MSRC).

Technical details

The root cause is an inappropriate implementation in Blink, Chrome's HTML rendering engine, classified as CWE-451 (User Interface Misrepresentation of Critical Information). An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by a victim on an Android device, causes the browser to misrepresent critical UI elements — enabling UI spoofing attacks such as faking address bar content, security indicators, or dialog prompts. Exploitation requires user interaction (e.g., visiting a malicious URL) but no special privileges. The Chromium issue tracker entry (ID 40057499) is access-restricted pending broad user patching (Chrome Releases).

Impact

Successful exploitation allows an attacker to spoof browser UI elements on Android, potentially deceiving users into believing they are on a trusted site or interacting with a legitimate security prompt. This primarily affects confidentiality and integrity at a low level — an attacker could trick users into submitting credentials or accepting malicious content under a false UI context. Availability is not impacted, and the scope is unchanged (limited to the browser process), but the social engineering potential of UI spoofing can amplify phishing and credential-harvesting attacks (Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify Android users running Google Chrome versions prior to 144.0.7559.59, potentially via user-agent detection on a controlled web server.
  2. Craft malicious HTML page: Develop a specially crafted HTML page that exploits the inappropriate Blink implementation to manipulate or spoof browser UI elements (e.g., fake address bar, security lock icon, or permission dialogs).
  3. Deliver the payload: Distribute the malicious URL via phishing emails, SMS (smishing), social media, or malicious advertisements targeting Android Chrome users.
  4. Victim interaction: When the victim visits the crafted page on a vulnerable Android Chrome browser, the Blink engine renders the page in a way that misrepresents critical UI information.
  5. Achieve objective: The spoofed UI deceives the victim into believing they are on a legitimate site, enabling credential harvesting, acceptance of malicious permissions, or other social engineering outcomes (Chrome Releases).

Indicators of compromise

  • Network: Unusual outbound connections from Android devices to unknown or newly registered domains; HTTP requests with suspicious referrer headers pointing to unfamiliar origins.
  • Logs: Browser access logs showing visits to suspicious or newly registered domains delivering complex HTML/JavaScript content targeting Android Chrome user-agents.
  • Process/Browser: Unexpected permission prompts or UI dialogs appearing on Chrome for Android without clear user-initiated action; address bar displaying unexpected or mismatched URLs relative to displayed page content.

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 144.0.7559.59 (Linux) and 144.0.7559.59/60 (Windows/Mac), released January 13, 2026; Android users should update to this version or later via the Google Play Store. Microsoft Edge (Chromium-based) users should apply the corresponding upstream fix referenced in the Microsoft Security Response Center advisory. No configuration-based workaround is available; updating to the patched version is the only recommended remediation. Organizations should ensure Chrome auto-update policies are enabled and verify endpoint compliance using vulnerability scanners (Qualys, Nessus detection IDs are available) (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 144 release received coverage from security news outlets including SecurityOnline, CyberSecurityNews, GBHackers, and CIS, primarily noting the batch of 10 security fixes including CVE-2026-0901. The CIS published an advisory noting that multiple vulnerabilities in Chrome 144 could allow for arbitrary code execution (referring to the broader release). Community reaction has been moderate given the Medium CVSS score and Android-specific scope. No notable individual researcher commentary beyond the original reporter (Irvan Kurniawan / sourc7) has been identified (CIS Advisory, Chrome Releases).

Additional resources

  • Chrome Releases — Official Google Chrome 144 stable channel release notes with security fix details
  • Microsoft MSRC — Microsoft Security Response Center advisory for Edge (Chromium)
  • CIS Advisory — CIS advisory on Chrome 144 vulnerabilities
  • Red Hat CVE — Red Hat security tracking for CVE-2026-0901
  • Palo Alto Advisory — Palo Alto Networks Chromium monthly vulnerability update (February 2026)

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management