Junglewise Threat Intelligence

CVE-2026-79011: Google Chrome UI misrepresentation in Browser

CVE-2026-79011 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's browser UI can be misrepresented through a crafted HTML page, allowing attackers to deceive users into bypassing system access restrictions. An attacker would leverage social engineering to trick users into interacting with a malicious webpage, potentially leading to unauthorized access or account compromise.

Technical details

This is a UI misrepresentation vulnerability in the Browser component of Google Chrome versions prior to 152.0.7977.65. The vulnerability allows a remote attacker to craft an HTML page that misrepresents the browser's UI elements, creating the appearance that the user is interacting with legitimate system dialogs or controls. The attack requires social engineering and user interaction with a malicious webpage. By exploiting this flaw, an attacker can bypass system access restrictions through deception. The fix is available in Chrome 152.0.7977.65 and later versions.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Chrome 152 stable release with fix
  • 2026-05-29: other: Vulnerability reported to Google

References

Related threats