CVE-2026-2320
vulnerability analysis and mitigation

Overview

CVE-2026-2320 is a UI spoofing vulnerability caused by an inappropriate implementation in the File input component of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported by Alesandro Ortiz on 2025-08-02 and publicly disclosed on February 10–11, 2026, as part of the Chrome 145 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Feedly).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's File input handling. A remote attacker can exploit this by crafting a malicious HTML page that, when a victim performs specific UI gestures (such as clicking or interacting with file input dialogs), causes the browser to render spoofed or misleading UI elements. Exploitation requires user interaction but no special privileges or authentication. Full technical details and the associated Chromium bug report (ID 435684924) remain restricted pending broad user adoption of the patch (Chrome Releases).

Impact

Successful exploitation allows an attacker to perform UI spoofing, potentially deceiving users into believing they are interacting with legitimate browser or operating system interface elements. This could facilitate phishing attacks, credential theft, or manipulation of users into performing unintended actions (e.g., granting file access or submitting sensitive data). The vulnerability has high integrity impact with no direct confidentiality or availability impact, and its scope is limited to the affected browser session (Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), released on February 10, 2026. Microsoft Edge (Chromium-based) is also affected and has a corresponding patch tracked via the Microsoft Security Response Center. Organizations should update all Chrome and Edge installations to the patched versions immediately. As a general precaution, users should be advised to exercise caution when interacting with file input dialogs on untrusted websites (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 145 update, which includes this fix among 11 total security patches, received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, primarily focusing on the higher-severity RCE-class vulnerabilities in the same release batch. Community discussion on Windows Forum touched on verifying the patch status for CVE-2026-2320 in Edge and Chrome via version checks. No notable researcher commentary specific to this CVE has been identified beyond the initial disclosure (GBHackers, CyberSecurityNews).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management