
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-93386 is a UI misrepresentation vulnerability in the WebAppInstalls component of Google Chrome that allows a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. It affects all versions of Google Chrome prior to 153.0.8010.52 on Windows, Mac, and Linux. The vulnerability was reported internally by Google on 2026-05-17 and publicly disclosed on 2026-09-17 alongside a stable channel update. It is rated Low severity by Chromium's security team, with an EPSS score of 0.0 (Chrome Release, GitHub Advisory).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning the browser fails to accurately represent critical UI state to the user during web app installation flows. An attacker can craft a malicious HTML page that manipulates how Chrome's WebAppInstalls interface renders, causing UI elements such as permission prompts or installation dialogs to appear misleading or spoofed. Exploitation requires the victim to visit a specially crafted web page, and success depends on social engineering — there is no memory corruption or authentication bypass involved. The Chromium bug tracker entry (issue 513996595) is currently restricted pending broad user update (Chrome Release).
Successful exploitation allows an attacker to deceive users into taking unintended actions — such as granting permissions or installing malicious web apps — by presenting spoofed Chrome UI elements. The primary impact is on integrity of user decision-making and potential unauthorized permission grants, rather than direct system compromise or data exfiltration. Because exploitation relies entirely on social engineering, the practical impact is limited to scenarios where users interact with and trust the spoofed UI (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date. The vulnerability has an EPSS score of 0.0 and is not listed in the CISA Known Exploited Vulnerabilities catalog. Exploitation requires user interaction and social engineering, significantly limiting its practical attack surface (GitHub Advisory).
Update Google Chrome to version 153.0.8010.52 or later (153.0.8010.52/.53 for Windows and Mac, 153.0.8010.52 for Linux), which was released on September 17, 2026. No configuration-based workaround is available; upgrading is the only remediation. As a supplementary measure, organizations should educate users to scrutinize web app installation prompts and be cautious when interacting with unfamiliar web pages (Chrome Release).
Coverage of this specific CVE has been minimal given its Low severity rating, though it was included in broader reporting on the Chrome 153 update that addressed 16 security fixes including two Critical-rated vulnerabilities. Security news outlets such as GBHackers covered the overall Chrome 153 security update (GBHackers).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."