CVE-2026-0907
vulnerability analysis and mitigation

Overview

CVE-2026-0907 is an incorrect security UI vulnerability in the Split View feature of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by security researcher Hafiizh on 2025-09-12 and publicly disclosed on January 13, 2026, as part of the Chrome 144 stable channel release. Affected versions include Google Chrome prior to 144.0.7559.59 (Linux) and 144.0.7559.60 (Windows/Mac), as well as Microsoft Edge Chromium. Google assigned this a Chromium security severity of Low, though CISA-ADP assigned a CVSS v3.1 base score of 9.8 (Critical) — a notable discrepancy reflecting differing risk assessments (Chrome Release Notes, Microsoft MSRC).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), specifically an incorrect rendering of security-relevant UI elements within Chrome's Split View mode. A remote attacker can craft a malicious HTML page that, when viewed in Split View, causes the browser to misrepresent or conceal critical security information — enabling UI spoofing attacks. No authentication or user interaction beyond visiting the crafted page is required for exploitation. The Chromium issue tracker entry (ID 444653104) is restricted pending broad user patching (Chrome Release Notes).

Impact

Successful exploitation allows a remote attacker to spoof browser security UI elements in Split View, potentially deceiving users into believing they are on a trusted or secure page when they are not. This could facilitate phishing, credential theft, or social engineering attacks by concealing address bar information, security indicators, or origin context. While the direct browser impact is UI deception rather than code execution, the downstream consequences — including credential compromise and data exfiltration — can be significant (Chrome Release Notes, Microsoft MSRC).

Exploitation steps

  1. Craft a malicious HTML page: Create a web page specifically designed to exploit the incorrect security UI rendering in Chrome's Split View mode, potentially mimicking a trusted site's visual elements or security indicators.
  2. Deliver the page to the target: Host the crafted page on an attacker-controlled server and lure the victim to open it in Chrome (e.g., via phishing email, malicious advertisement, or social engineering).
  3. Trigger Split View rendering: The page is designed to be opened or manipulated in Chrome's Split View mode, causing the browser to incorrectly render or suppress security UI elements (e.g., address bar, origin indicators, HTTPS lock icon).
  4. Perform UI spoofing: With security indicators misrepresented, the attacker can deceive the user into believing they are on a legitimate, trusted site — enabling credential harvesting, phishing, or other social engineering attacks.

Note: Specific technical payloads are not publicly available as the Chromium issue tracker entry (ID 444653104) remains restricted (Chrome Release Notes).

Indicators of compromise

  • Network: Unexpected outbound connections from Chrome to unfamiliar domains while Split View is active; traffic patterns consistent with phishing page delivery.
  • Logs: Browser history or proxy logs showing visits to suspicious or newly registered domains that attempt to mimic legitimate sites, particularly when accessed via Split View.
  • Process/Behavior: Chrome rendering pages in Split View with suppressed or altered address bar content; users reporting unexpected UI behavior or missing security indicators in Split View mode.

Note: No specific IOCs have been publicly documented for this vulnerability, as no in-the-wild exploitation has been confirmed.

Mitigation and workarounds

Update Google Chrome to version 144.0.7559.59 (Linux) or 144.0.7559.60 (Windows/Mac) or later, released January 13, 2026. Microsoft Edge Chromium users should apply the patch released January 16, 2026, via the Microsoft Security Response Center. No configuration-based workaround has been published; upgrading to the patched version is the only recommended remediation. Organizations should also ensure Chromium-based distributions (Debian, Fedora, openSUSE) are updated via their respective package managers (Chrome Release Notes, Microsoft MSRC).

Community reactions

The CIS (Center for Internet Security) issued an advisory noting multiple vulnerabilities in Chrome 144 that could allow for arbitrary code execution, grouping CVE-2026-0907 with higher-severity issues in the same release. Forbes covered the Chrome 144 update broadly, noting new security issues confirmed for billions of users. The Hacker Wire published commentary specifically on the Split View UI spoofing issue, characterizing it as a "critical deception" vulnerability despite its Low Chromium severity rating. The discrepancy between Google's Low severity classification and CISA-ADP's CVSS 9.8 score generated discussion in the security community, with some noting the score may be inflated relative to the actual exploitation complexity.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management