Description
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-01
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Google Chrome prior to 152.0.7977.75 has a UI misrepresentation flaw that becomes active when a page is displayed in full-screen mode. A malicious web page can cause the Chrome address bar to show a forged URL, allowing a remote attacker to deceive a user into believing they are viewing a different site. The weakness corresponds to CWE‑451 and results in information disclosure by misrepresenting the page’s identity, potentially enabling phishing or social engineering attacks. No data execution or server compromise is possible from the flaw alone.

Affected Systems

The vulnerability affects the stable channel of Google Chrome browsers running any operating system, specifically versions older than 152.0.7977.75. Any installation of Chrome before that version is susceptible when it renders a page in full‑screen mode.

Risk and Exploitability

The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. The CVE severity is marked low, and the attack requires a remote attacker to host a crafted HTML page that a user visits while the browser is in full‑screen mode. Because the flaw does not grant code execution or privileged access, the overall risk is moderate, primarily arising from social engineering.

Generated by OpenCVE AI on September 2, 2026 at 03:58 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to 152.0.7977.75 or later
  • If an update cannot be applied immediately, restrict or disable full-screen mode for untrusted content by adjusting browser settings or using an extension that blocks full-screen transitions
  • Educate users to verify the actual address bar and be wary of UI representations, especially when webpages request full-screen

Generated by OpenCVE AI on September 2, 2026 at 03:58 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Google Chrome FullScreen UI Spoofing

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-01T23:42:30.059Z

Reserved: 2026-09-01T16:21:34.451Z

Link: CVE-2026-84356

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T00:18:29.523

Modified: 2026-09-02T00:18:29.523

Link: CVE-2026-84356

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:09Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information