Description
UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Bypass of System Access via UI Misrepresentation
Action: Patch
AI Analysis

Impact

The vulnerability is a UI misrepresentation in Web Authentication (Passkeys & Security Keys) that existed in Google Chrome before version 152.0.7977.65. A crafted HTML page can trick the user into performing an authentication action that bypasses system access restrictions, effectively allowing remote exploitation through social engineering. The weakness corresponds to CWE‑451, reflecting a misleading user interface. The impact is unauthorized system access, potentially compromising confidentiality and integrity of the affected machine by permitting a user to log in or authenticate without proper verification.

Affected Systems

Google Chrome, all releases prior to 152.0.7977.65. The vulnerability was identified in the stable channel of Chrome on desktop.

Risk and Exploitability

CVSS score is 6.5, and the EPSS score is less than 1%. The vulnerability is not listed in CISA KEV. Exploitation requires a crafted web page and social engineering, so the risk is limited to users who visit malicious sites. Because the vulnerability allows a user to bypass authentication, a patch is advised even though exploitation conditions remain user‑dependent.

Generated by OpenCVE AI on August 27, 2026 at 19:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or newer
  • Disable or limit Web Authentication for untrusted origins until the issue is fixed
  • Educate users about phishing risks and teach them to recognize potentially misleading passkey prompts

Generated by OpenCVE AI on August 27, 2026 at 19:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Mon, 31 Aug 2026 17:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Enables System Bypass via Crafted HTML in Chrome

Thu, 27 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Enables System Bypass via Crafted HTML in Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Web Authentication (Passkeys & Security Keys) in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to bypass system access restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T15:19:44.940Z

Reserved: 2026-08-25T06:09:29.356Z

Link: CVE-2026-79108

cve-icon Vulnrichment

Updated: 2026-08-27T15:19:28.899Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:06.103

Modified: 2026-08-31T16:53:48.440

Link: CVE-2026-79108

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information