Impact
The vulnerability lies in the TabStrip UI component of Google Chrome, where a crafted HTML page can cause the browser to render misleading UI elements. This allows a remote attacker to trick users into interacting with deceptive controls, potentially leading to fraud or social engineering. The weakness is identified as CWE‑451.
Affected Systems
Affected product is Google Chrome on desktop platforms, versions earlier than 154.0.8037.92. Users running any pre‑154.0.8037.92 release are susceptible.
Risk and Exploitability
The CVSS score of 5.4 places the issue in the moderate range. No EPSS score is available, and it is not listed in the CISA KEV catalog. The attack vector is remote and does not require privileged or local access; a malicious webpage hosted by the attacker can trigger the issue. Users can mitigate by updating to a patched Chrome release.
OpenCVE Enrichment