Impact
The flaw is a UI misrepresentation in Google Chrome versions earlier than 152.0.7977.65. A remote attacker can serve a carefully crafted HTML page and, by exploiting social‑engineering tactics, trick a user into interacting with a UI that appears legitimate but actually grants access to restricted system resources. This vulnerability is categorized as CWE‑451. If the user engages with the manipulated interface, the attacker could elevate privileges or access the system without authorization.
Affected Systems
Google Chrome browsers running any build before 152.0.7977.65 on supported platforms are affected, including all major releases of the stable channel that had not yet received the August 2026 patch.
Risk and Exploitability
The vulnerability is rated high severity with a CVSS score of 8.1. Exploitation requires user interaction with a malicious page, making social engineering the primary attack vector. The EPSS score is < 1% and the flaw is not listed in CISA KEV. Once a user clicks a deceptive element presented by the crafted HTML, the UI misrepresentation allows bypass of standard access controls.
OpenCVE Enrichment
Debian DLA
Debian DSA