Description
UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
Published: 2026-08-25
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: System access bypass via UI deception
Action: Immediate Patch
AI Analysis

Impact

The flaw is a UI misrepresentation in Google Chrome versions earlier than 152.0.7977.65. A remote attacker can serve a carefully crafted HTML page and, by exploiting social‑engineering tactics, trick a user into interacting with a UI that appears legitimate but actually grants access to restricted system resources. This vulnerability is categorized as CWE‑451. If the user engages with the manipulated interface, the attacker could elevate privileges or access the system without authorization.

Affected Systems

Google Chrome browsers running any build before 152.0.7977.65 on supported platforms are affected, including all major releases of the stable channel that had not yet received the August 2026 patch.

Risk and Exploitability

The vulnerability is rated high severity with a CVSS score of 8.1. Exploitation requires user interaction with a malicious page, making social engineering the primary attack vector. The EPSS score is < 1% and the flaw is not listed in CISA KEV. Once a user clicks a deceptive element presented by the crafted HTML, the UI misrepresentation allows bypass of standard access controls.

Generated by OpenCVE AI on August 31, 2026 at 16:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Chrome update to version 152.0.7977.65 or later immediately.
  • Ensure Chrome’s Safe Browsing and phishing protection features are enabled to help detect deceptive UI attacks.
  • Use endpoint or web‑filtering solutions to block domains known to host malicious HTML pages that exploit UI misrepresentation.

Generated by OpenCVE AI on August 31, 2026 at 16:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Enables System Access Bypass in Google Chrome

Mon, 31 Aug 2026 15:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Mon, 31 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Enables System Access Bypass in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: High)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-31T13:49:40.395Z

Reserved: 2026-08-25T06:07:16.777Z

Link: CVE-2026-79011

cve-icon Vulnrichment

Updated: 2026-08-31T13:49:35.346Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:56.863

Modified: 2026-08-31T15:03:32.183

Link: CVE-2026-79011

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T16:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information