Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.1 Browsers CVE-2026-95321 CVE-2026-95307 CVE-2026-95337 CVE-2026-95291

Google Chrome Patches Eight UI Spoofing and Authorization Flaws (154.0.8037.57)

Google has fixed eight medium-to-low severity Chrome vulnerabilities affecting the address bar, UI elements, extensions menu, navigation, and NFC handling across Desktop, Android, iOS, and Mac. All are resolved in version 154.0.8037.57.

AI summary

Google has released Chrome version 154.0.8037.57 for Desktop, addressing eight separate vulnerabilities disclosed under CVE-2026-95321, CVE-2026-95307, CVE-2026-95337, CVE-2026-95291, CVE-2026-95288, CVE-2026-95320, CVE-2026-95371, and CVE-2026-95370. The issues span multiple Chrome components — including Payments, ExtensionsMenu, Messages, SecurityIndicators, Mobile, Navigation, Views, and NFC — and affect various platforms (Android, iOS, Mac, and Desktop generally). All eight were disclosed via the Chrome Stable Channel Update blog post and are tracked in NVD.

What happened

Google published a Stable Channel Update for Chrome Desktop disclosing eight vulnerabilities, all rated Chromium security severity Medium or Low, and all fixed in version 154.0.8037.57. The group includes UI misrepresentation issues (CWE-451) that could allow a remote attacker to spoof UI elements or the address bar via a crafted HTML page (CVE-2026-95321, CVE-2026-95307, CVE-2026-95337, CVE-2026-95291, CVE-2026-95288), missing authorization issues (CWE-862) that could allow an attacker who had already compromised the renderer process to spoof the address bar or UI elements (CVE-2026-95320, CVE-2026-95371), and an inappropriate implementation issue in NFC handling (CWE-841) that could allow a remote attacker to bypass system access restrictions via a crafted HTML page (CVE-2026-95370).

Technical cause

The vulnerabilities fall into three categories. Five are UI misrepresentation flaws (CWE-451) affecting components such as Payments, ExtensionsMenu, Messages, SecurityIndicators, and Mobile, where a crafted HTML page could cause Chrome to display misleading or spoofed UI, including the address bar in some cases. Two are missing authorization flaws (CWE-862) in the Navigation and Views components, which required an attacker to have already compromised the renderer process before the spoofing could occur. One is an inappropriate implementation flaw (CWE-841) in NFC handling that could let an attacker bypass system access restrictions via a crafted HTML page. All eight share the same CVSS base score of 5.4, with most requiring some form of user interaction and, for several, social engineering.

Why it matters

UI spoofing vulnerabilities, particularly those affecting the address bar or security indicators, can be used to deceive users about the true origin or trustworthiness of a page, which can facilitate phishing or social-engineering attacks. The two missing-authorization issues require prior compromise of the renderer process, meaning they would likely be chained with another vulnerability rather than exploited in isolation. The NFC-related issue could allow bypass of system access restrictions on supported platforms. None of these issues allow memory corruption or direct code execution on their own, based on the information provided.

Who is affected

Users and organizations running Google Chrome prior to version 154.0.8037.57 are affected. Specific issues apply to particular platforms: CVE-2026-95321 and CVE-2026-95337 affect Chrome on Android; CVE-2026-95291 and CVE-2026-95288 affect Chrome on iOS; CVE-2026-95371 affects Chrome on Mac; CVE-2026-95307, CVE-2026-95320, and CVE-2026-95370 are described generally for Google Chrome without a specific platform designation in the provided descriptions.

Discovery and timeline

All eight vulnerabilities were disclosed on September 22, 2026 via Google's Chrome Stable Channel Update blog post, with corresponding NVD entries published on September 29, 2026. The fact package does not identify a discoverer for any of these issues, and no claims of active exploitation or public proof-of-concept exploits are included in the available information.

Affected versions

All eight vulnerabilities affect Google Chrome versions prior to 154.0.8037.57. No lower bound of the affected version range is specified in the available data.

Fixes and mitigation

Google has released version 154.0.8037.57, which resolves all eight vulnerabilities described in this briefing. No workarounds or mitigations other than updating are mentioned in the source material.

Recommended action

Update Google Chrome to version 154.0.8037.57 or later on all affected platforms (Desktop, Android, iOS, and Mac as applicable) as soon as possible. Chrome typically updates automatically, but users and administrators should verify the installed version via the browser's About page and restart the browser to complete the update.

PatchBriefing score

4.1 / 10 · Medium

Official CVSS: 5.4

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L

Why this score

Each vulnerability carries a CVSS base score of 5.4 (CVSS:3.1), reflecting network attack vector, low attack complexity, no privileges required, but required user interaction and limited impact on confidentiality and, in one case, integrity, with no impact on availability for most. The computed PatchWire score of 4.1 reflects this moderate base severity, combined with the facts that these are unauthenticated remote issues (contributing a small increase) and affect a widely used product (Chrome), while no known exploitation, no public exploit code, and an available fix keep the overall score moderate rather than high.

Affected versions

≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched
≥ 154.0.8037.57
patched

Reported fixes

Google has released version 154.0.8037.57, which resolves all eight vulnerabilities described in this briefing. No workarounds or mitigations other than updating are mentioned in the source material.

How this was built

9 source records were collected, matched and used to prepare the report above.

  • Chrome Releases (Stable) vendor
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
  • NVD (NIST) database
Unified report
Google Chrome Patches Eight UI Spoofing and Authorization Flaws (154.0.8037.57)
1 article · 9 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email