Junglewise Threat Intelligence

CVE-2026-79009: Google Chrome UI misrepresentation via crafted HTML

CVE-2026-79009 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely-used web browser used to access websites and online services. A UI misrepresentation vulnerability allows an attacker to spoof browser interface elements through a specially crafted webpage, potentially deceiving users into performing unintended actions such as clicking fake buttons, entering credentials into fake forms, or accepting unwanted permissions. This vulnerability requires social engineering to exploit but could undermine user trust and lead to credential theft or malware installation.

Technical details

This is a UI misrepresentation vulnerability in Google Chrome's user interface rendering. The flaw allows a remote attacker to craft a malicious HTML page that deceives users by spoofing legitimate browser UI elements, bypassing visual security indicators. The attack vector is network-based and requires user interaction (social engineering) to visit the crafted webpage; no authentication or elevated privileges are needed on the attacker side. An attacker can exploit this to trick users into granting permissions, entering sensitive data into fake forms, or clicking on malicious links disguised as legitimate browser controls. The vulnerability was fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux).

Affected products

  • Google Chrome prior to 152.0.7977.65 (Windows/Mac), prior to 152.0.7977.64 (Linux)

Timeline

  • 2026-08-25: disclosed: Fixed in Chrome 152.0.7977.65/64

References

Related threats