Executive brief
Google Chrome's password manager contains an authorization flaw that allows a remote attacker with access to the browser's rendering process to spoof security UI elements through a crafted webpage. An attacker exploiting this vulnerability could trick users into disclosing sensitive information or performing unintended actions by impersonating legitimate Chrome interface elements, potentially compromising stored credentials and user trust.
Technical details
This vulnerability is a missing authorization flaw in Chrome's Passwords component (CVE-2026-79058). The vulnerability requires the attacker to have already compromised the renderer process, meaning code execution is a prerequisite. The attack vector is network-based and involves crafting a malicious HTML page that, when rendered, exploits the missing authorization check to spoof UI elements related to password management. An attacker can achieve UI spoofing of password-related interface elements, which could be used in social engineering attacks to extract credentials or sensitive user data. The vulnerability was fixed in Chrome 152.0.7977.65 released on August 25, 2026.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65