CVE-2026-0907User Interface (UI) Misrepresentation of Critical Information in Google Chrome

Severity
9.8CRITICALNVD
EPSS
0.1%
top 68.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 20
Latest updateJan 27

Description

Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

CVEListV5google/chrome144.0.7559.59144.0.7559.59
NVDgoogle/chrome< 144.0.7559.59+1
Debianchromium/chromium< 144.0.7559.59-1~deb12u1+2

🔴Vulnerability Details

3
OSV
CVE-2026-0907: Incorrect security UI in Split View in Google Chrome prior to 1442026-01-20
GHSA
GHSA-m5g9-928c-q4jg: Incorrect security UI in Split View in Google Chrome prior to 1442026-01-20
CVEList
CVE-2026-0907: Incorrect security UI in Split View in Google Chrome prior to 1442026-01-20

📋Vendor Advisories

4
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-09072026-01-27
Red Hat
chromium-browser: Incorrect security UI in Split View2026-01-13
Microsoft
Chromium: CVE-2026-0907 Incorrect security UI in Split View2026-01-13
Debian
CVE-2026-0907: chromium - Incorrect security UI in Split View in Google Chrome prior to 144.0.7559.59 allo...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0907 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0907 — Google Chrome vulnerability | cvebase