
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2316 is a UI spoofing vulnerability caused by insufficient policy enforcement in Frames in Google Chrome. It allows a remote attacker to perform UI spoofing via a crafted HTML page, potentially deceiving users into interacting with fraudulent browser interface elements. The vulnerability affects Google Chrome versions prior to 145.0.7632.45 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). It was reported by security researcher Luan Herrera (@lbherrera_) on 2025-06-05 and publicly disclosed on February 10–11, 2026, when Chrome 145 was released to the stable channel. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Feedly).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from insufficient policy enforcement in Chrome's Frames component. An attacker can craft a malicious HTML page that, when visited by a victim, manipulates frame-level rendering or policy boundaries to misrepresent browser UI elements — such as the address bar, security indicators, or dialog boxes — making malicious content appear legitimate. Exploitation requires no privileges and no special configuration, but does require user interaction (visiting a crafted page). Bug details remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows an attacker to spoof the browser's user interface, potentially tricking users into clicking fraudulent links, entering credentials into fake forms, or approving unintended actions by making malicious content appear to be legitimate browser UI. The impact is limited to integrity violations — there is no confidentiality or availability impact, and the vulnerability does not enable direct code execution or data exfiltration on its own. However, it could serve as a component in a broader phishing or social engineering attack chain (Feedly).
Google has released Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac) which addresses this vulnerability. Microsoft has also issued a corresponding update for Microsoft Edge (Chromium-based). Organizations should update all Chrome and Edge installations to the patched versions immediately. As a supplementary measure, user awareness training about unexpected browser UI behavior and caution when visiting untrusted websites is recommended. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Releases, Microsoft MSRC).
The Chrome 145 release received broad coverage from security news outlets including GBHackers, CyberSecurityNews, SecurityOnline, and CyberPress, primarily in the context of the full 11-vulnerability patch batch rather than CVE-2026-2316 specifically. A Reddit thread on r/pwnhub discussed the Chrome 145 fixes, noting the three high-severity flaws as the primary concern. WindowsForum published an explainer specifically on CVE-2026-2316 covering the UI spoofing mechanism and Edge patch status. The vulnerability was awarded a $5,000 bug bounty by Google, reflecting its medium severity classification (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."