Executive brief
Google Chrome is a web browser used by millions to access websites and web applications. A vulnerability in Chrome's core UI rendering on macOS allows an attacker who has already compromised the browser's rendering process to display fake UI elements that could trick users into taking unintended actions, potentially leading to credential theft or unwanted system changes.
Technical details
This is a UI misrepresentation vulnerability in Chrome's Core component affecting macOS systems prior to version 152.0.7977.65. The vulnerability allows a remote attacker who has already compromised the renderer process to spoof UI elements by serving a crafted HTML page. The attack requires prior compromise of the renderer process, limiting the attack surface compared to renderer escapes. The fix is available in Chrome 152.0.7977.65 and later versions. Google assessed this as Low severity in their security framework, though it is tracked as CVE-2026-79284 with a CVSS 3.1 score of 4.3 (Medium).
Affected products
- Google Chrome prior to 152.0.7977.65 on macOS
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched: Chrome 152.0.7977.65 released