Junglewise Threat Intelligence

CVE-2026-79022: Google Chrome UI misrepresentation in Transactions Platform

CVE-2026-79022 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Transactions Platform contains a UI spoofing vulnerability that allows attackers to disguise malicious website content as legitimate browser interface elements. An attacker can leverage social engineering via a crafted HTML page to trick users into taking actions they believe are safe, potentially leading to unauthorized transactions, credential theft, or other user-initiated attacks. The vulnerability affects Chrome versions prior to 152.0.7977.65.

Technical details

This is a UI misrepresentation vulnerability in Chrome's Transactions Platform component that allows remote attackers to spoof browser UI elements. The vulnerability is triggered via a crafted HTML page and requires social engineering to be effective—the attacker cannot force an action but can deceive a user into clicking or interacting with spoofed UI. The attack is network-reachable and requires no authentication. An attacker can potentially trick users into confirming fraudulent transactions or providing sensitive information by making web content appear as trusted browser UI. The vulnerability was patched in Chrome 152.0.7977.65 (and 152.0.7977.64 for Linux).

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: Published by Chrome Security team
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats