Junglewise Threat Intelligence

CVE-2026-79176: Google Chrome UI misrepresentation in Extensions

CVE-2026-79176 · Severity: medium · CVSS 6.5 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome contains a flaw in its Extensions feature that allows malicious browser extensions to misrepresent themselves to users through deceptive UI manipulation. An attacker can craft a malicious extension and distribute it through social engineering, tricking users into installing it to steal sensitive information such as passwords, browsing data, or personal credentials. This vulnerability puts users' data at risk and could lead to unauthorized access to accounts and services.

Technical details

This vulnerability is a UI misrepresentation flaw in the Chrome Extensions component, classified as medium severity by the Chromium security team. The root cause involves the Extension feature failing to properly represent the true identity or permissions of installed extensions to the user, allowing a malicious extension to hide its true nature or capabilities behind deceptive UI elements. The attack vector is social engineering—an attacker must convince a user to install a malicious extension, requiring user interaction. Once installed, the extension can intercept and exfiltrate sensitive information. The vulnerability affects Chrome versions prior to 152.0.7977.65 on Windows, Mac, and Linux, and is addressed in Chrome 152 and later.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65

References

Related threats