CVE-2026-106305: UI misrepresentation in Google Chrome
Description
A UI misrepresentation vulnerability exists in Google Chrome for Android versions prior to 155.0.8059.39. This flaw allows a remote attacker to spoof UI elements via a crafted HTML page, potentially misleading users. The vulnerability is rated as medium severity with a CVSS score of 5.4. A fix has been released in version 155.0.8059.39.
CVSS v3.1
Score 5.4medium
Affected software
Chrome
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-106305 is a UI misrepresentation vulnerability affecting Google Chrome on Android platforms before version 155.0.8059.39. The issue allows remote attackers to craft HTML pages that spoof user interface elements, potentially deceiving users. The vulnerability has a CVSS 3.1 base score of 5.4, indicating medium severity. According to the vendor advisory, the issue is addressed in Chrome version 155.0.8059.39.
Potential Impact
The vulnerability enables remote attackers to spoof UI elements in the Chrome mobile browser on Android, which could mislead users into interacting with deceptive content. The impact is limited to UI misrepresentation with no direct confidentiality or integrity compromise reported. The CVSS vector indicates low complexity and no privileges required, but user interaction is necessary.
Mitigation Recommendations
Users should update Google Chrome on Android to version 155.0.8059.39 or later to remediate this vulnerability. The vendor has released an official fix as noted in the Chrome stable channel update advisory. No additional mitigation steps are required beyond applying this update.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Chrome
- Date Reserved
- 2026-10-06T16:34:43.736Z
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://chromereleases.googleblog.com/2026/10/stable-channel-update-for-desktop_086471744.html","vendor":"Google"}]
Threat ID: 6ac5464b2cdf04f656d49dc5
Added to database: 10/06/2026, 19:04:43 UTC
Last enriched: 10/06/2026, 21:34:10 UTC
Last updated: 10/06/2026, 21:34:10 UTC
Views: 4
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.