5.4
CVE-2026-87655
- EPSS 0.18%
- Veröffentlicht 09.09.2026 00:09:50
- Zuletzt bearbeitet 09.09.2026 20:27:04
- Erkennungen
Clickjacking in Downloads in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.18% | 0.079 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
|
CWE-1021 Improper Restriction of Rendered UI Layers or Frames
The web application does not restrict or incorrectly restricts frame objects or UI layers that belong to another application or domain.
https://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop_0808145027.html
https://issues.chromium.org/issues/514023309