Description
UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote UI Spoofing
Action: Update Browser
AI Analysis

Impact

The flaw is a UI misrepresentation that lets a remote attacker introduce a crafted HTML page to deceive users into interacting with spoofed interface elements. The remote attacker can manipulate the visual appearance of UI components, potentially tricking users into performing unintended actions or revealing sensitive information. This weakness is classified under CWE‑451.

Affected Systems

Google Chrome versions earlier than 152.0.7977.65 on desktop platforms are affected. The issue affects the stable channel and any users who have not applied the current patch.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity vulnerability. The EPSS score is less than 1%, and the flaw is not listed in the CISA KEV catalog. The attack requires a malicious web page and a social‑engineering vector; a remote attacker can load a crafted page to spoof UI elements and trick users into interacting with deceptive interface components.

Generated by OpenCVE AI on August 27, 2026 at 19:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 152.0.7977.65 or newer to eliminate the UI spoofing flaw.
  • Restrict or disable third‑party extensions that inject custom HTML into web pages, as they could be exploited to create spoofed interfaces.
  • Educate users to recognize and avoid phishing attempts that rely on UI spoofing and to verify that the browser's UI reflects the expected layout.

Generated by OpenCVE AI on August 27, 2026 at 19:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Crafted HTML

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Chrome UI Spoofing via Crafted HTML

Tue, 25 Aug 2026 22:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in UI in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:27:09.216Z

Reserved: 2026-08-25T06:07:14.799Z

Link: CVE-2026-79009

cve-icon Vulnrichment

Updated: 2026-08-27T15:27:06.208Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:56.643

Modified: 2026-08-28T14:40:58.747

Link: CVE-2026-79009

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:15:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information