Description
UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-08-25
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Address Bar Spoofing via Navigation UI Misrepresentation
Action: Update Browser
AI Analysis

Impact

Google Chrome before version 152.0.7977.65 contained a flaw that allowed a remote attacker to create a crafted HTML page which, when opened in the browser, caused the navigation UI to display a spoofed address bar. The misrepresentation can mislead users into believing the browser is visiting a different site than it actually is, potentially enabling phishing or social‑engineering attacks.

Affected Systems

All users running any version of Google Chrome prior to 152.0.7977.65 on any platform are affected, as the vulnerability is specific to the desktop browser’s navigation UI.

Risk and Exploitability

The exploitation requires the victim to visit a malicious web page, so it is a browser‑based attack that depends on user interaction. The CVSS score is 5.4, classified as medium, indicating that while the flaw does not allow arbitrary code execution, it can significantly undermine user trust in the browser’s interface and create an environment conducive to credential theft or other social‑engineering attacks. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog.

Generated by OpenCVE AI on August 28, 2026 at 18:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 152.0.7977.65 or newer using the official release channels
  • Enable Chrome’s automatic update feature to ensure future patches are applied promptly
  • Disable or uninstall any browser extensions that modify the navigation UI or address bar representation, which could interfere with the browser’s integrity checks

Generated by OpenCVE AI on August 28, 2026 at 18:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Fri, 28 Aug 2026 18:45:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Allows Address Bar Spoofing in Google Chrome

Fri, 28 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}


Wed, 26 Aug 2026 03:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 26 Aug 2026 02:45:00 +0000

Type Values Removed Values Added
Title UI Misrepresentation Allows Address Bar Spoofing in Google Chrome

Tue, 25 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-27T18:56:13.145Z

Reserved: 2026-08-25T06:12:35.264Z

Link: CVE-2026-79250

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2026-08-25T21:18:19.440

Modified: 2026-08-28T14:33:19.803

Link: CVE-2026-79250

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T18:30:08Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information