Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-87655
vulnerability analysis and mitigation

Overview

CVE-2026-87655 is a clickjacking vulnerability in the Downloads feature of Google Chrome that allows a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.36 on Windows, Mac, and Linux. The vulnerability was reported to Google on May 17, 2026, and publicly disclosed on September 8–9, 2026, as part of the Chrome 153 stable channel release. It carries a CVSS v3.1 base score of 5.4 (Medium) (Github Advisory, Chrome Release).

Technical details

The vulnerability is classified under CWE-1021 (Improper Restriction of Rendered UI Layers or Frames), meaning Chrome's Downloads UI does not adequately restrict or validate rendered UI layers, allowing an attacker-controlled page to overlay or obscure legitimate download interface elements (Github Advisory). An attacker crafts a malicious HTML page that uses transparent or opaque overlays (e.g., iframes or CSS-positioned elements) to visually hijack the Chrome Downloads UI, tricking users into interacting with spoofed elements while believing they are interacting with legitimate Chrome UI. Exploitation requires user interaction — specifically, a victim must visit the attacker's crafted page — and no authentication or special privileges are required on the attacker's side. The Chromium issue tracker references this bug under issue ID 514023309 (Chrome Release).

Impact

Successful exploitation can deceive users into initiating unintended file downloads or confirming download actions they did not intend, potentially leading to malware delivery or unwanted file execution. The CVSS assessment indicates a low confidentiality impact (e.g., limited information disclosure through UI interaction) and a low availability impact, with no direct integrity impact (Github Advisory). The attack is limited in scope to the affected browser session and does not directly enable lateral movement or system-level compromise, but could serve as an initial vector for social engineering-based malware distribution (Red Hat Bugzilla).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation for CVE-2026-87655 as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.237%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Exploitation is not automatable and requires user interaction, further limiting its practical exploitability (Chrome Release).

Exploitation steps

  1. Reconnaissance: Identify users running Google Chrome versions prior to 153.0.8010.36 — this can be inferred through browser fingerprinting techniques on a malicious or compromised website.
  2. Craft malicious HTML page: Create a webpage that renders a transparent or visually deceptive overlay (e.g., using CSS z-index, opacity, or iframe layering) positioned over the Chrome Downloads UI elements.
  3. Lure victim: Use phishing, malvertising, or social engineering to direct the target user to the crafted page while they are engaged in a download activity or trigger a download from the page itself.
  4. UI spoofing: When the Chrome Downloads bar or dialog appears, the attacker's overlay intercepts or mimics the UI, causing the user to click on a spoofed element (e.g., a fake "Open" or "Save" button) instead of the legitimate Chrome control.
  5. Achieve objective: The user unknowingly confirms or initiates an unintended download action, potentially executing a malicious file or disclosing interaction data to the attacker (Github Advisory, Chrome Release).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser to unfamiliar domains immediately following a download prompt interaction; HTTP requests to domains hosting pages with suspicious iframe or overlay structures targeting Chrome download UI.
  • File System: Unexpected files appearing in the user's Downloads directory that the user did not intentionally download; executable files (.exe, .msi, .dmg, .sh) downloaded without user awareness.
  • Logs: Browser history or download history logs showing downloads initiated from unfamiliar or suspicious URLs; Chrome download logs reflecting files saved without explicit user confirmation.
  • Process: Unexpected processes launched from the Downloads directory shortly after a browser session involving suspicious pages.

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 153.0.8010.36 (Linux) and 153.0.8010.36/.37 (Windows/Mac), released on September 8, 2026. Users should update Google Chrome to version 153.0.8010.36 or later immediately via the browser's built-in update mechanism (Settings > Help > About Google Chrome) (Chrome Release). As a behavioral workaround, users should exercise caution when visiting untrusted websites and verify that download dialogs are legitimate before confirming any file downloads. Enterprise administrators can enforce Chrome version policies via Google Admin Console or Microsoft MSRC guidance to ensure fleet-wide patching (Microsoft MSRC).

Community reactions

The vulnerability was noted in security community aggregators and vulnerability tracking platforms shortly after disclosure, including coverage on security-next.com and cyberpress.org, which highlighted the broader Chrome 153 update containing 230 security fixes (Chrome Release). No notable independent researcher commentary or significant social media discussion specific to CVE-2026-87655 has been identified, consistent with its medium severity rating and lack of active exploitation. The broader Chrome 153 release attracted attention primarily due to the critical-severity CVEs and the confirmed in-the-wild exploit for CVE-2026-87491.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

chromium: 153.0.8010.47-1

Fixed

sid

chromium: 153.0.8010.47-1

Fixed

trixie

chromium: 153.0.8010.47-2~deb13u1

Fixed

SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management