Spoofing attack in Google Chromium - CVE-2026-79108
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to spoof the user interface.
The vulnerability exists due to ui misrepresentation in Web Authentication (Passkeys & Security Keys) when rendering authentication-related browser interface elements. A remote attacker can present misleading authentication interface content to spoof the user interface.
User interaction is required.
Affected software
Microsoft Edge
Google Chrome
Debian Linux
chromium (Debian package)
How to mitigate CVE-2026-79108
Microsoft Edge - update to 152.0.4191.53
Google Chrome - addressed in versions 151.0.7922.175, 152.0.7977.64
chromium (Debian package) - update to 152.0.7977.75-1~deb13u1