Description
UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive information disclosure via UI misrepresentation in Chrome extensions
Action: Update Browser
AI Analysis

Impact

A flaw in how Google Chrome renders and represents the user interface of extensions allows a remote attacker to use social engineering to trick a user into installing a crafted extension, which can then access sensitive data. The vulnerability corresponds to CWE-451, representing a misrepresentation that can lead to unintended user actions. The direct effect is the potential for confidential data to be disclosed to an attacker.

Affected Systems

Google Chrome browsers version 152.0.7977.64 and earlier are affected. The issue is tied to the Chrome UI handling of extensions prior to the 152.0.7977.65 release. Users on any platform running the vulnerable Chrome version are susceptible if they install or use a malicious extension crafted by an attacker.

Risk and Exploitability

Chromium rates the vulnerability as Medium severity, with a CVSS score of 6.5. Exploitation relies on a user accepting a malicious extension, which requires a social‑engineering attack. The EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the widespread usage of Chrome and the ubiquity of extensions mean that the risk remains significant for users who do not regularly update their browsers or scrutinize extension permissions.

Generated by OpenCVE AI on August 26, 2026 at 21:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 152.0.7977.65 or newer
  • Remove or block untrusted or suspicious extensions
  • Verify extension permissions and only install extensions from official trusted sources

Generated by OpenCVE AI on August 26, 2026 at 21:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 26 Aug 2026 22:00:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Misrepresentation Allows Data Disclosure

Wed, 26 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 01:30:00 +0000

Type Values Removed Values Added
Title Chrome Extension UI Misrepresentation Allows Data Disclosure

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Extensions in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering to obtain sensitive information via a crafted Chrome extension. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-26T18:44:50.202Z

Reserved: 2026-08-25T06:10:53.298Z

Link: CVE-2026-79176

cve-icon Vulnrichment

Updated: 2026-08-26T18:10:01.853Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:11.157

Modified: 2026-08-27T17:48:34.850

Link: CVE-2026-79176

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-26T21:45:03Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information