
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2320 is a UI spoofing vulnerability caused by an inappropriate implementation in the File input component of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45 on Windows, Mac, and Linux. The vulnerability was reported by Alesandro Ortiz on 2025-08-02 and publicly disclosed on February 10–11, 2026, as part of the Chrome 145 stable channel release. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Feedly).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's File input handling. A remote attacker can exploit this by crafting a malicious HTML page that, when a victim performs specific UI gestures (such as clicking or interacting with file input dialogs), causes the browser to render spoofed or misleading UI elements. Exploitation requires user interaction but no special privileges or authentication. Full technical details and the associated Chromium bug report (ID 435684924) remain restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows an attacker to perform UI spoofing, potentially deceiving users into believing they are interacting with legitimate browser or operating system interface elements. This could facilitate phishing attacks, credential theft, or manipulation of users into performing unintended actions (e.g., granting file access or submitting sensitive data). The vulnerability has high integrity impact with no direct confidentiality or availability impact, and its scope is limited to the affected browser session (Feedly).
Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), released on February 10, 2026. Microsoft Edge (Chromium-based) is also affected and has a corresponding patch tracked via the Microsoft Security Response Center. Organizations should update all Chrome and Edge installations to the patched versions immediately. As a general precaution, users should be advised to exercise caution when interacting with file input dialogs on untrusted websites (Chrome Releases, Microsoft MSRC).
The Chrome 145 update, which includes this fix among 11 total security patches, received coverage from several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, primarily focusing on the higher-severity RCE-class vulnerabilities in the same release batch. Community discussion on Windows Forum touched on verifying the patch status for CVE-2026-2320 in Edge and Chrome via version checks. No notable researcher commentary specific to this CVE has been identified beyond the initial disclosure (GBHackers, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."