
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2322 is a low-severity UI spoofing vulnerability caused by an inappropriate implementation in the File input component of Google Chrome. It affects all versions of Google Chrome prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Robbe Van Roey (PinkDraconian) on 2025-12-22 and patched on February 10, 2026, with public disclosure on February 11, 2026. It carries a CVSS v3.1 base score of 5.4 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, Microsoft MSRC).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's File input handling. A remote attacker can craft a malicious HTML page that, when a user performs specific UI gestures (e.g., clicking or interacting with a file input element), causes the browser to render a spoofed UI, potentially misleading the user about the nature of the action being performed. Exploitation requires user interaction and network access, but no authentication or elevated privileges. A separate but related Medium-severity File input flaw (CVE-2026-2320) was patched in the same Chrome 145 release (Chrome Releases).
Successful exploitation allows an attacker to deceive users into performing unintended actions by spoofing browser UI elements, primarily affecting integrity and availability at a low level with no direct confidentiality impact. The spoofing could be leveraged in social engineering scenarios — for example, tricking users into selecting or uploading sensitive files, or confirming actions they did not intend. The scope is limited to the browser session and does not directly enable code execution or system compromise (Chrome Releases).
<input type="file"> element with manipulated styling, overlays, or event handling designed to misrepresent the UI to the victim.<input type="file"> elements.Update Google Chrome to version 145.0.7632.45 or later on all platforms (Windows, Mac, Linux), which was released on February 10, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding patched Edge update. No configuration-based workaround is available; upgrading is the only remediation. Organizations should also educate users to exercise caution when interacting with unfamiliar websites and to verify UI prompts before confirming file-related actions (Chrome Releases, Microsoft MSRC).
Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the Chrome 145 security update, noting the 11 fixes included in the release. The vulnerability received a $1,000 bug bounty reward from Google, reflecting its low severity rating. A blog post from undercodetesting.com discussed the flaw under the framing of a "regression bypass," though this characterization has not been independently corroborated by major security vendors (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."