Description
UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-09-01
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Address Bar Spoofing
Action: Apply Patch
AI Analysis

Impact

Google Chrome prior to 152.0.7977.75 has a UI misrepresentation flaw that becomes active when a page is displayed in full‑screen mode. Based on the description, it is inferred that the attack vector is a malicious web page that a user visits while Chrome is in full‑screen mode. A malicious web page can cause the Chrome address bar to show a forged URL, allowing a remote attacker to deceive a user into believing they are viewing a different site. The weakness corresponds to CWE‑451 and results in information disclosure by misrepresenting the page’s identity, potentially enabling phishing or social engineering attacks. No data execution or server compromise is possible from the flaw alone.

Affected Systems

The vulnerability affects the stable channel of Google Chrome browsers running any operating system, specifically versions older than 152.0.7977.75. Any installation of Chrome before that version is susceptible when it renders a page in full‑screen mode.

Risk and Exploitability

The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. The CVSS score is 4.3, reflecting a low‑to‑moderate severity; the attack requires a remote attacker to host a crafted HTML page that a user visits while the browser is in full‑screen mode. Because the flaw does not grant code execution or privileged access, the overall risk remains moderate and primarily arises from social engineering.

Generated by OpenCVE AI on September 3, 2026 at 10:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to 152.0.7977.75 or later
  • If an update cannot be applied immediately, restrict or disable full‑screen mode for untrusted content by adjusting browser settings or using an extension that blocks full‑screen transitions
  • Educate users to verify the actual address bar and be wary of UI representations, especially when webpages request full‑screen

Generated by OpenCVE AI on September 3, 2026 at 10:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4771-1 chromium security update
Debian DSA Debian DSA DSA-6482-1 chromium security update
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 17:45:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

Wed, 02 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 0.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}


Wed, 02 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Title Google Chrome FullScreen UI Spoofing chromium-browser: chromium-browser: UI misrepresentation in FullScreen
Weaknesses CWE-1021
References
Metrics threat_severity

None

cvssV3_1

{'score': 0.0, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:N'}

threat_severity

Low


Wed, 02 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Title Google Chrome FullScreen UI Spoofing

Wed, 02 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 02 Sep 2026 00:00:00 +0000

Type Values Removed Values Added
Description UI misrepresentation in FullScreen in Google Chrome prior to 152.0.7977.75 allowed a remote attacker to spoof address bar via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-451
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-09-17T19:05:18.828Z

Reserved: 2026-09-01T16:21:34.451Z

Link: CVE-2026-84356

cve-icon Vulnrichment

Updated: 2026-09-02T18:39:51.301Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-02T00:18:29.523

Modified: 2026-09-03T17:25:55.253

Link: CVE-2026-84356

cve-icon Redhat

Severity : Low

Publid Date: 2026-09-01T23:42:30Z

Links: CVE-2026-84356 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T11:00:03Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information