Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious… (CVE-2026-17755)
A vulnerability in Google Chrome prior to version 151.0.7922.72 involves incorrect security UI handling in the Extensions feature. This flaw allows an attacker who convinces a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. The issue has a medium severity rating and does not impact confidentiality or availability but can lead to integrity issues through UI deception.
AI Analysis
Technical Summary
CVE-2026-17755 is a vulnerability in Google Chrome's Extensions UI prior to version 151.0.7922.72. The vulnerability arises from incorrect security UI implementation, enabling an attacker to spoof the user interface by convincing a user to install a malicious extension. This UI spoofing can mislead users about the extension's permissions or actions, potentially facilitating further attacks. The vulnerability has a CVSS 3.1 base score of 4.3 (medium severity), with no known exploits in the wild. It does not affect confidentiality or availability but impacts integrity due to UI deception. No patch or remediation information is provided in the available data.
Potential Impact
The vulnerability allows an attacker to perform UI spoofing via a malicious Chrome extension, potentially misleading users about extension permissions or actions. This can result in integrity issues by tricking users into trusting malicious extensions. There is no direct impact on confidentiality or availability. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should update Google Chrome to version 151.0.7922.72 or later once the update is available. Until then, users should exercise caution when installing extensions, especially those from untrusted sources.
Incorrect security UI in Extensions in Google Chrome prior to 151.0.7922.72 allowed an attacker who convinced a user to install a malicious… (CVE-2026-17755)
Description
A vulnerability in Google Chrome prior to version 151.0.7922.72 involves incorrect security UI handling in the Extensions feature. This flaw allows an attacker who convinces a user to install a malicious extension to perform UI spoofing via a crafted Chrome Extension. The issue has a medium severity rating and does not impact confidentiality or availability but can lead to integrity issues through UI deception.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-17755 is a vulnerability in Google Chrome's Extensions UI prior to version 151.0.7922.72. The vulnerability arises from incorrect security UI implementation, enabling an attacker to spoof the user interface by convincing a user to install a malicious extension. This UI spoofing can mislead users about the extension's permissions or actions, potentially facilitating further attacks. The vulnerability has a CVSS 3.1 base score of 4.3 (medium severity), with no known exploits in the wild. It does not affect confidentiality or availability but impacts integrity due to UI deception. No patch or remediation information is provided in the available data.
Potential Impact
The vulnerability allows an attacker to perform UI spoofing via a malicious Chrome extension, potentially misleading users about extension permissions or actions. This can result in integrity issues by tricking users into trusting malicious extensions. There is no direct impact on confidentiality or availability. No known exploits have been reported in the wild.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Users should update Google Chrome to version 151.0.7922.72 or later once the update is available. Until then, users should exercise caution when installing extensions, especially those from untrusted sources.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-6vmp-jgfm-6r3v
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-17755"]
- Database Specific Severity
- MODERATE
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a710662bf32cb7a34394100
Added to database: 08/03/2026, 21:21:38 UTC
Last enriched: 08/03/2026, 21:30:06 UTC
Last updated: 09/11/2026, 19:31:53 UTC
Views: 38
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.