Description
UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Crafted Pages
Action: Update Browser
AI Analysis

Impact

An attacker can load a specially crafted web page and use the Transactions Platform in Google Chrome to misuse how user interface elements are displayed. The vulnerability allows the UI to be misrepresented, enabling a malicious page to forge or alter transaction prompts and other graphics that a user trusts, which can be leveraged for social‑engineering attacks. The flaw does not permit execution of arbitrary code but can lead to the user making unintended actions or revealing sensitive information. The weakness is a form of untrusted input without proper validity checks.

Affected Systems

All users of Google Chrome with a version earlier than 152.0.7977.65 are affected. The flaw exists in the Transactions Platform component of the browser and affects all installations where that component is active.

Risk and Exploitability

The EPSS score of < 1% indicates a very low exploitation probability, and the CVSS score of 4.3 confirms low severity. Because the flaw relies on a user interacting with a malicious web page, exploitation requires social engineering and user action. The Chromium security severity is rated low, indicating that the impact is limited to UI deception and potential phishing rather than direct code execution or system compromise. As no publicly disclosed exploits are known and the risk is contingent on user interaction, the overall likelihood of exploitation is considered low, though vigilance is still warranted.

Generated by OpenCVE AI on August 27, 2026 at 19:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (152.0.7977.65 or newer).
  • If the Transactions Platform is unnecessary for your workflow, disable or restrict its use through Chrome settings or feature flags.
  • Continue to exercise caution with transaction‑related prompts, rely on Chrome's built‑in phishing detection, or use reputable extensions that warn about suspicious UI elements.

Generated by OpenCVE AI on August 27, 2026 at 19:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Multiple UI Spoofing via Crafted Web Pages in Google Chrome Prior to 152.0.7977.65

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 25 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
Title Multiple UI Spoofing via Crafted Web Pages in Google Chrome Prior to 152.0.7977.65

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Transactions Platform in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to potentially spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:33:35.468Z

Reserved: 2026-08-25T06:07:43.589Z

Link: CVE-2026-79022

cve-icon Vulnrichment

Updated: 2026-08-27T15:33:32.346Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:17:58.080

Modified: 2026-08-28T14:40:29.030

Link: CVE-2026-79022

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information