
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2323 is a UI spoofing vulnerability caused by an inappropriate implementation in the Downloads component of Google Chrome. It allows a remote attacker to perform UI spoofing via a crafted HTML page, potentially deceiving users into taking unintended actions. The vulnerability was reported by security researcher Hafiizh on December 10, 2025, and publicly disclosed on February 10–11, 2026, with the release of Chrome 145. It affects all versions of Google Chrome prior to 145.0.7632.45, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, Microsoft MSRC).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), stemming from an inappropriate implementation in Chrome's Downloads subsystem. An attacker can craft a malicious HTML page that manipulates how download-related UI elements are rendered or presented to the user, causing the browser to misrepresent critical information such as file names, origins, or download prompts. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed on the attacker's side. No public proof-of-concept code has been identified (Chrome Releases, Feedly).
Successful exploitation results in a low integrity impact with no confidentiality or availability impact, as classified by the CVSS score. An attacker could deceive users into believing they are interacting with a legitimate browser dialog or downloading a trusted file, potentially leading them to execute malicious content or disclose sensitive information through social engineering. The scope is limited to the affected browser session and does not directly enable lateral movement or system-level compromise, but it can serve as a stepping stone in a broader phishing or malware delivery campaign (Feedly).
document.pdf.exe) that may have been obscured by UI spoofing.~/.config/google-chrome/Default/History on Linux, %LOCALAPPDATA%\Google\Chrome\User Data\Default\History on Windows) referencing unexpected file sources.Google has addressed this vulnerability in Chrome 145.0.7632.45 (Linux) and 145.0.7632.45/46 (Windows/Mac), released on February 10, 2026. Microsoft has also issued guidance for Edge (Chromium-based) users via the MSRC advisory. Users should update Google Chrome and Microsoft Edge to the latest available version immediately. No configuration-based workaround is available; upgrading is the only effective remediation. Organizations should also enforce browser update policies via enterprise management tools and consider user awareness training around download prompt interactions (Chrome Releases, Microsoft MSRC).
The vulnerability received routine coverage as part of the broader Chrome 145 security update, which patched 11 vulnerabilities in total. Security news outlets including GBHackers, CyberSecurityNews, and CyberPress covered the Chrome 145 release, primarily focusing on the higher-severity RCE-class vulnerabilities in the same update. The Windows Forum community discussed the patch status for Microsoft Edge in relation to CVE-2026-2323. No significant independent researcher commentary or notable social media discussion specific to this low-severity issue has been identified (Chrome Releases, Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."