Executive brief
Google Chrome is a web browser used by billions of users worldwide to access web applications and services. A UI misrepresentation vulnerability in the WebAppInstalls component allows a remote attacker to spoof UI elements through a crafted HTML page, potentially tricking users into performing unintended actions or believing they are interacting with legitimate browser interface elements.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's WebAppInstalls component that allows remote attackers to spoof browser UI elements via a crafted HTML page. The attack is delivered over the network without requiring prior authentication or special user interaction beyond visiting a malicious web page. An attacker can leverage this to deceive users by displaying fake UI elements that appear to be legitimate Chrome interface components, potentially leading to credential theft, malware installation, or other social engineering attacks. The vulnerability was patched in Chrome version 152.0.7977.65 and later.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Fixed in Chrome 152.0.7977.65