Executive brief
Google Chrome's Downloads feature contained a privilege management flaw that could allow an attacker who had already compromised the browser's rendering engine to spoof the address bar—potentially deceiving users about which website they are visiting. This could facilitate phishing attacks or malware distribution by making malicious content appear to come from trusted sites.
Technical details
The vulnerability is an improper privilege management issue in the Downloads component of Google Chrome versions prior to 152.0.7977.75. It requires the attacker to have already compromised the renderer process, from which they can craft a malicious HTML page to spoof the address bar. While the attack vector is limited to a compromised renderer, the impact is address bar spoofing—a high-confidence phishing vector. The Chromium project assigned this a Medium security severity. The fix is available in Chrome version 152.0.7977.75 and later.
Affected products
- Google Chrome prior to 152.0.7977.75
Timeline
- 2026-09-02: disclosed
- 2026-09-02: patched: Fixed in Chrome 152.0.7977.75