Description
Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing
Action: Immediate Patch
AI Analysis

Impact

Missing authorization in the password handling flow of Google Chrome allowed a remote attacker who had already compromised the renderer process to spoof user interface elements via a crafted HTML page. This flaw enables an attacker to display counterfeit controls or prompts, potentially tricking users into revealing sensitive information. The weakness is a classic authorization bypass, classified as CWE‑862.

Affected Systems

Google Chrome on desktop platforms is vulnerable until the patch that addresses the flaw is installed.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity exploitation potential. The EPSS score of 0.00232 (<1%) indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog, indicating that it is not yet widely exploited. The attack requires the attacker to compromise the renderer process, which typically implies local or remote code execution context within the browser. Because the flaw is high severity, attackers may simply use the compromised renderer to perform phishing or UI deception after establishing control over the browser environment.

Generated by OpenCVE AI on August 27, 2026 at 19:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to the latest available version that includes the fix.
  • Ensure that renderer process isolation and sandboxing features are enabled through Chrome's security settings.
  • Disable or restrict any remote debugging interfaces that could allow external code injection into the renderer process.

Generated by OpenCVE AI on August 27, 2026 at 19:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title Password UI Spoofing by Compromised Renderer in Google Chrome

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title Password UI Spoofing by Compromised Renderer in Google Chrome

Tue, 25 Aug 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description Missing authorization in Passwords in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the renderer process to spoof UI elements via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-862
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:28:08.856Z

Reserved: 2026-08-25T06:08:25.040Z

Link: CVE-2026-79058

cve-icon Vulnrichment

Updated: 2026-08-27T15:28:03.955Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:01.707

Modified: 2026-08-31T16:37:09.353

Link: CVE-2026-79058

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:45:03Z

Weaknesses