Junglewise Threat Intelligence

CVE-2026-79204: Google Chrome UI misrepresentation in Input

CVE-2026-79204 · Severity: medium · CVSS 5.4 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome is a web browser used by millions to access online services and content. A UI misrepresentation vulnerability allows attackers to spoof browser interface elements (such as address bars or security indicators) through a crafted web page, potentially tricking users into performing actions they did not intend, such as entering credentials or approving permissions on fake interfaces.

Technical details

This vulnerability is a UI misrepresentation flaw in Chrome's Input handling on macOS. An attacker can craft a malicious HTML page that visually spoofs legitimate browser UI elements, deceiving users about the true origin or safety status of a webpage. The attack requires only network access and user interaction (visiting a malicious page); no authentication or privileges are needed. An attacker can exploit this to conduct phishing attacks or trick users into granting permissions they would otherwise refuse. The vulnerability is fixed in Chrome 152.0.7977.65 and later for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched

References

Related threats