Executive brief
Google Chrome's permission dialog element can be visually spoofed through a crafted web page, allowing attackers to trick users into granting permissions they did not intend to grant. An attacker would need to socially engineer a user to visit a malicious website that displays a fake or misleading permission dialog, potentially leading to unauthorized access to sensitive browser features like camera, microphone, or location data.
Technical details
This vulnerability is a UI misrepresentation flaw in the PermissionElement component of Google Chrome prior to version 152.0.7977.65. The vulnerability allows an attacker to spoof UI elements via a crafted HTML page, leveraging social engineering to deceive users. The attack requires user interaction—specifically visiting a malicious web page and responding to a fraudulent permission prompt. An attacker can exploit this to gain unauthorized access to sensitive device permissions. The vulnerability has been patched in Chrome 152.0.7977.65 and later versions.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65