Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-79283

CVE-2026-79283: Google Chrome Geometry XSS Vulnerability

CVE-2026-79283 is a cross-site scripting vulnerability in Google Chrome Geometry that enables UI spoofing through crafted HTML pages. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-79283 Overview

CVE-2026-79283 is a UI misrepresentation vulnerability in the Geometry component of Google Chrome prior to version 152.0.7977.65. A remote attacker can spoof user interface elements by serving a crafted HTML page to a victim. Google Chromium rates the security severity as Medium.

The flaw is categorized under CWE-451: User Interface (UI) Misrepresentation of Critical Information. Successful exploitation enables spoofing attacks that mislead users about the origin, trust level, or intent of on-screen content. Such misrepresentation supports phishing, credential theft, and social engineering campaigns targeting Chrome users.

Critical Impact

Attackers can craft HTML pages that visually deceive Chrome users, enabling convincing phishing and social engineering attacks against any user browsing untrusted content.

Affected Products

  • Google Chrome desktop versions prior to 152.0.7977.65
  • Chromium-based browsers that share the affected Geometry rendering code
  • All operating system builds distributed through the Chrome Stable channel prior to the update

Discovery Timeline

  • 2026-08-25 - CVE-2026-79283 published to NVD
  • 2026-08-26 - Last updated in NVD database

Technical Details for CVE-2026-79283

Vulnerability Analysis

The vulnerability resides in Chrome's Geometry code, which handles positioning, sizing, and layout calculations for browser UI elements and rendered web content. Improper handling of geometric properties permits attacker-controlled HTML to render content that overlaps, mimics, or obscures trusted browser UI.

Users rely on browser chrome, such as the address bar, permission prompts, and security indicators, to make trust decisions. When rendered geometry can be manipulated by a page, the visual boundary between web content and browser UI collapses. Attackers can present fake URLs, forged permission dialogs, or spoofed security warnings.

Because the attack is delivered through a normal HTML page, no authentication or prior compromise is required. The victim only needs to visit a malicious site or a compromised page that loads attacker-controlled content.

Root Cause

The root cause is a UI misrepresentation weakness [CWE-451] in Chrome's Geometry handling. The rendering path does not sufficiently constrain how attacker-supplied HTML influences the visual layout of critical trust-conveying elements, allowing spoofed content to appear authoritative to the user.

Attack Vector

Exploitation requires a remote attacker to lure a user to a crafted HTML page. The attacker constructs page elements whose geometry produces a misleading visual state, such as covering the origin indicator or presenting a fake dialog aligned with browser UI. No memory corruption occurs; the impact is user deception leading to secondary attacks like credential harvesting.

No public proof-of-concept, exploit code, or in-the-wild exploitation has been reported. The EPSS probability is low, consistent with a Medium-rated spoofing issue rather than a code execution flaw. See the Chromium Issue #518035396 and the Google Chrome Stable Update announcement for vendor details.

Detection Methods for CVE-2026-79283

Indicators of Compromise

  • Chrome desktop clients reporting a version string below 152.0.7977.65 in browser inventory or user-agent telemetry
  • Web proxy logs showing user navigation to newly registered or low-reputation domains hosting HTML pages that mimic known login portals
  • User reports of unexpected permission prompts, address bar anomalies, or dialogs that do not match visited sites

Detection Strategies

  • Correlate endpoint browser version telemetry against the fixed build 152.0.7977.65 to identify exposed hosts
  • Monitor DNS and HTTP telemetry for indicators of phishing infrastructure and typosquatted domains targeting corporate SSO or SaaS applications
  • Inspect user-reported phishing submissions for HTML payloads that manipulate CSS positioning, iframes, or overlays consistent with UI spoofing

Monitoring Recommendations

  • Enable managed browser reporting to centralize Chrome version and extension inventory across the fleet
  • Track credential submission events to non-corporate domains through secure web gateway or identity provider logs
  • Alert on repeated authentication failures immediately following user visits to newly observed external domains

How to Mitigate CVE-2026-79283

Immediate Actions Required

  • Update all Google Chrome desktop installations to version 152.0.7977.65 or later through the Stable channel
  • Force a browser relaunch on managed endpoints to ensure the patched binary is active, since Chrome only applies updates after restart
  • Audit Chromium-derived browsers in the environment and apply upstream fixes as vendors release them

Patch Information

Google addressed the issue in Chrome Stable 152.0.7977.65. Details are published in the Google Chrome Stable Update announcement and tracked as Chromium Issue #518035396. Enterprises using Chrome Browser Cloud Management or group policy should confirm the target version is enforced.

Workarounds

  • Restrict browsing to trusted sites through URL filtering or secure web gateway policies until the patch is deployed
  • Reinforce user awareness that browser UI elements, including address bars and permission prompts, can be spoofed by crafted pages
  • Require phishing-resistant authentication such as FIDO2 security keys to reduce the impact of successful spoofing

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.