Executive brief
Google Chrome is a web browser used by millions to access online services and content. A UI misrepresentation vulnerability allows attackers to spoof browser interface elements (such as address bars or security indicators) through a crafted web page, potentially tricking users into performing actions they did not intend, such as entering credentials or approving permissions on fake interfaces.
Technical details
This vulnerability is a UI misrepresentation flaw in Chrome's Input handling on macOS. An attacker can craft a malicious HTML page that visually spoofs legitimate browser UI elements, deceiving users about the true origin or safety status of a webpage. The attack requires only network access and user interaction (visiting a malicious page); no authentication or privileges are needed. An attacker can exploit this to conduct phishing attacks or trick users into granting permissions they would otherwise refuse. The vulnerability is fixed in Chrome 152.0.7977.65 and later for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 152.0.7977.65
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched