
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-87655 is a clickjacking vulnerability in the Downloads feature of Google Chrome that allows a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.36 on Windows, Mac, and Linux. The vulnerability was reported to Google on May 17, 2026, and publicly disclosed on September 8–9, 2026, as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, Chrome Release).
The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), meaning Chrome's Downloads UI does not adequately restrict or validate rendered UI layers, allowing an attacker-controlled page to overlay or obscure legitimate download interface elements (Github Advisory). An attacker crafts a malicious HTML page that uses transparent or opaque overlays (e.g., iframes or CSS-positioned elements) to visually hijack the Chrome Downloads UI, tricking users into interacting with spoofed elements while believing they are interacting with legitimate Chrome UI. Exploitation requires user interaction — specifically, a victim must visit the attacker's crafted page — and no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references this bug under issue ID 514023309 (Chrome Release).
Successful exploitation can deceive users into initiating unintended file downloads or confirming download actions they did not intend, potentially leading to malware delivery or unwanted file execution. The CVSS assessment indicates a low confidentiality impact (e.g., limited information disclosure through UI interaction) and a low availability impact, with no direct integrity impact (Github Advisory). The attack is limited in scope to the affected browser session and does not directly enable lateral movement or system-level compromise, but could serve as an initial vector for social engineering-based malware distribution (Red Hat Bugzilla).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-87655 as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.237%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation is not automatable and requires user interaction, further limiting its practical exploitability (Chrome Release).
z-index, opacity, or iframe layering) positioned over the Chrome Downloads UI elements..exe, .msi, .dmg, .sh) downloaded without user awareness.Google has addressed this vulnerability in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/Mac), released on September 8, 2026. Users should update Google Chrome to version 153.0.8010.36 or later immediately via the browser's built-in update mechanism (Settings > Help > About Google Chrome) (Chrome Release). As a behavioral workaround, users should exercise caution when visiting untrusted websites and verify that download dialogs are legitimate before confirming any file downloads. Enterprise administrators can enforce Chrome version policies via Google Admin Console or Microsoft MSRC guidance to ensure fleet-wide patching (Microsoft MSRC).
The vulnerability was noted in security community aggregators and vulnerability tracking platforms shortly after disclosure, including coverage on security-next.com and cyberpress.org, which highlighted the broader Chrome 153 update containing 230 security fixes (Chrome Release). No notable independent researcher commentary or significant social media discussion specific to CVE-2026-87655 has been identified, consistent with its medium severity rating and lack of active exploitation. The broader Chrome 153 release attracted attention primarily due to the critical-severity CVEs and the confirmed in-the-wild exploit for CVE-2026-87491.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."