Junglewise Threat Intelligence

CVE-2026-79108: Google Chrome UI misrepresentation in Web Authentication

CVE-2026-79108 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's Web Authentication feature (used for passkeys and security keys) displays misleading interface elements that could trick users into authorizing access they did not intend. An attacker could exploit this UI flaw through a crafted webpage to bypass system access restrictions via social engineering, potentially leading to unauthorized account access or data exposure.

Technical details

This vulnerability is a UI misrepresentation flaw in Chrome's Web Authentication (WebAuthn) implementation for passkeys and security keys. The attack vector is network-based and relies on social engineering; a remote attacker crafts a malicious HTML page that exploits the misleading UI to deceive users into approving authentication attempts they should not permit. No special privileges or local access are required—only user interaction with a crafted webpage. The vulnerability allows attackers to bypass system access restrictions by tricking users through interface manipulation. The fix is available in Chrome 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 and later

References

Related threats