Junglewise Threat Intelligence

CVE-2026-79173: Google Chrome UI misrepresentation in WebAppInstalls

CVE-2026-79173 · Severity: medium · CVSS 5.4 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a web browser used by billions of users worldwide to access web applications and services. A UI misrepresentation vulnerability in the WebAppInstalls component allows a remote attacker to spoof UI elements through a crafted HTML page, potentially tricking users into performing unintended actions or believing they are interacting with legitimate browser interface elements.

Technical details

This vulnerability is a UI misrepresentation flaw in Chrome's WebAppInstalls component that allows remote attackers to spoof browser UI elements via a crafted HTML page. The attack is delivered over the network without requiring prior authentication or special user interaction beyond visiting a malicious web page. An attacker can leverage this to deceive users by displaying fake UI elements that appear to be legitimate Chrome interface components, potentially leading to credential theft, malware installation, or other social engineering attacks. The vulnerability was patched in Chrome version 152.0.7977.65 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats