Junglewise Threat Intelligence

CVE-2026-78974: Google Chrome UI misrepresentation in Linux Toolkit Theming

CVE-2026-78974 · Severity: medium · CVSS 5.4 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Linux contains a flaw in how it renders themed UI elements, which could allow an attacker to disguise malicious content or controls through social engineering. An attacker could craft a deceptive webpage that tricks users into granting system access or permissions they would not normally allow, potentially compromising system security.

Technical details

This vulnerability is a UI misrepresentation flaw in the Linux Toolkit Theming component of Google Chrome, classified as Low severity by the Chromium security team. The vulnerability allows a remote attacker to bypass system access restrictions through social engineering by crafting a malicious HTML page that exploits how the themed UI is rendered on Linux systems. The attack requires user interaction (the victim must visit a crafted webpage and fall for the social engineering) and relies on the visual deception enabled by improper UI representation. The fix is available in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats