Junglewise Threat Intelligence

CVE-2026-79284: Google Chrome UI misrepresentation in Core on Mac

CVE-2026-79284 · Severity: medium · CVSS 4.3 · Published 2026-08-25

Technologies: Apple macOS, Google Chrome. Vendors: Apple, Google.

Executive brief

Google Chrome is a web browser used by millions to access websites and web applications. A vulnerability in Chrome's core UI rendering on macOS allows an attacker who has already compromised the browser's rendering process to display fake UI elements that could trick users into taking unintended actions, potentially leading to credential theft or unwanted system changes.

Technical details

This is a UI misrepresentation vulnerability in Chrome's Core component affecting macOS systems prior to version 152.0.7977.65. The vulnerability allows a remote attacker who has already compromised the renderer process to spoof UI elements by serving a crafted HTML page. The attack requires prior compromise of the renderer process, limiting the attack surface compared to renderer escapes. The fix is available in Chrome 152.0.7977.65 and later versions. Google assessed this as Low severity in their security framework, though it is tracked as CVE-2026-79284 with a CVSS 3.1 score of 4.3 (Medium).

Affected products

  • Google Chrome prior to 152.0.7977.65 on macOS

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Chrome 152.0.7977.65 released

References

Related threats