Junglewise Threat Intelligence

CVE-2026-79283: Google Chrome UI misrepresentation in Geometry

CVE-2026-79283 · Severity: medium · CVSS 5.4 · Published 2026-08-25

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser deployed across millions of devices. A UI misrepresentation vulnerability in the browser's Geometry component allows attackers to craft deceptive web pages that spoof user interface elements, potentially tricking users into performing unintended actions such as granting permissions or clicking malicious links.

Technical details

This is a UI misrepresentation vulnerability (CWE-451) in the Geometry component of Google Chrome. A remote attacker can craft a malicious HTML page that exploits this flaw to spoof or misrepresent UI elements within the browser, deceiving users about what actions they are taking. The attack requires only network access and user interaction (visiting a crafted web page); no prior authentication or special user privileges are needed. The vulnerability was fixed in Chrome version 152.0.7977.65 and later releases. Google assigned this vulnerability a Medium severity rating with a CVSS v3 score of 5.4.

Affected products

  • Google Chrome prior to 152.0.7977.65

Timeline

  • 2026-08-25: disclosed: CVE-2026-79283 published; Chrome 152.0.7977.65 released with fix
  • 2026-08-25: patched: Fixed in Chrome 152.0.7977.65 (Windows/Mac) and 152.0.7977.64 (Linux)

References

Related threats