Executive brief
Google Chrome is a widely-used web browser that runs on Windows, Mac, and Linux. A vulnerability allows attackers to craft malicious web pages that spoof or mislead users about security-critical UI elements (like address bars or warning dialogs), potentially tricking users into trusting fraudulent content or disabling security protections.
Technical details
This is a UI misrepresentation vulnerability in the Browser component of Google Chrome. The flaw allows remote attackers to spoof browser UI elements via a crafted HTML page, exploiting how the browser renders or validates user interface components. The attack requires user interaction (visiting a malicious page) over the network. The vulnerability was patched in Chrome 152.0.7977.65 for Windows/Mac and 152.0.7977.64 for Linux, released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65 (Windows/Mac), prior to 152.0.7977.64 (Linux)
Timeline
- 2026-08-25: disclosed: Chrome 152 released with fix
- 2026-08-25: patched: Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)