CVE-2026-2322
vulnerability analysis and mitigation

Overview

CVE-2026-2322 is a low-severity UI spoofing vulnerability caused by an inappropriate implementation in the File input component of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Robbe Van Roey (PinkDraconian) on 2025-12-22 and patched on February 10, 2026, with public disclosure on February 11, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's File input handling. A remote attacker can craft a malicious HTML page that, when a user performs specific UI gestures (e.g., clicking or interacting with a file input element), causes the browser to render a spoofed UI, potentially misleading the user about the nature of the action being performed. Exploitation requires user interaction and network access, but no authentication or elevated privileges. A separate but related Medium-severity File input flaw (CVE-2026-2320) was patched in the same Chrome 145 release (Chrome Releases).

Impact

Successful exploitation allows an attacker to deceive users into performing unintended actions by spoofing browser UI elements, primarily affecting integrity and availability at a low level with no direct confidentiality impact. The spoofing could be leveraged in social engineering scenarios — for example, tricking users into selecting or uploading sensitive files, or confirming actions they did not intend. The scope is limited to the browser session and does not directly enable code execution or system compromise (Chrome Releases).

Exploitation steps

  1. Reconnaissance: Identify users running Google Chrome versions prior to 145.0.7632.45 or unpatched Microsoft Edge (Chromium-based) builds.
  2. Craft malicious HTML page: Develop a webpage containing a specially crafted <input type="file"> element with manipulated styling, overlays, or event handling designed to misrepresent the UI to the victim.
  3. Social engineering delivery: Distribute the crafted page via phishing email, malicious advertisement, or compromised website to lure the target into visiting it.
  4. Trigger UI gestures: Wait for or prompt the user to interact with the file input element (e.g., clicking a button that appears to perform a benign action).
  5. Achieve spoofing objective: The inappropriate implementation causes the browser to display misleading UI, potentially causing the user to unknowingly select and upload a sensitive file or confirm an unintended action (Chrome Releases).

Indicators of compromise

  • Network: Outbound HTTP/HTTPS requests from the browser to unexpected external domains immediately following file input interactions; traffic to newly registered or low-reputation domains hosting crafted HTML pages.
  • Logs: Browser history or proxy logs showing visits to suspicious pages with file input manipulation patterns; web server logs showing delivery of HTML pages with obfuscated or complex <input type="file"> elements.
  • Process: Unexpected file upload activity initiated from the browser process to external endpoints without explicit user intent.

Mitigation and workarounds

Update Google Chrome to version 145.0.7632.45 or later on all platforms (Windows, Mac, Linux), which was released on February 10, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding patched Edge update. No configuration-based workaround is available; upgrading is the only remediation. Organizations should also educate users to exercise caution when interacting with unfamiliar websites and to verify UI prompts before confirming file-related actions (Chrome Releases, Microsoft MSRC).

Community reactions

Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the Chrome 145 security update, noting the 11 fixes included in the release. The vulnerability received a $1,000 bug bounty reward from Google, reflecting its low severity rating. A blog post from undercodetesting.com discussed the flaw under the framing of a "regression bypass," though this characterization has not been independently corroborated by major security vendors (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management