Description
UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: UI Spoofing via Crafted Input
Action: Upgrade Browser
AI Analysis

Impact

The vulnerability is a UI misrepresentation flaw in the input handling of Google Chrome on macOS, discovered before version 152.0.7977.65. A malicious web page can provide crafted HTML that masquerades native UI controls, leading the user to believe they are interacting with legitimate browser prompts. This spoofing can be abused to trick users into providing credentials or sensitive information. Chromium categorised the issue as Medium severity. The flaw does not lead to code execution.

Affected Systems

Affected systems are Google Chrome users on macOS devices running any Chrome version before 152.0.7977.65. The vulnerability was fixed in subsequent releases, beginning with the stable channel update released in August 2026. No other vendors or product lines are impacted according to the available CNA data.

Risk and Exploitability

The EPSS score is <1% and the vulnerability is not listed in the KEV catalogue, indicating a low but non‑zero exploitation probability. The attack vector is inferred as a user loading a malicious HTML page that contains crafted input designed to mimic native UI controls. While the flaw does not provide code execution or privilege escalation, the spoofed UI can facilitate phishing or credential theft when a user interacts with the deceptive elements. The CVSS score of 5.4 indicates medium severity.

Generated by OpenCVE AI on August 28, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 152.0.7977.65 or newer from the official update channel.
  • Ensure automatic Chrome updates are enabled so subsequent patches are applied promptly.
  • Exercise caution when entering credentials on pages that display unexpected or unfamiliar UI elements; verify that such prompts originate from a trusted source.

Generated by OpenCVE AI on August 28, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 19:15:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Input in Chrome for Mac

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 26 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title UI Spoofing via Crafted Input in Chrome for Mac
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T18:56:37.212Z

Reserved: 2026-08-25T06:11:28.099Z

Link: CVE-2026-79204

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:14.277

Modified: 2026-08-28T14:35:56.077

Link: CVE-2026-79204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T19:00:11Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information