Impact
The vulnerability exists in Chrome’s download handling logic and allows a remote attacker to load a specially crafted HTML page that can spoof the browser’s user interface. By masquerading as a legitimate site or function, the attacker can deceive the user into interacting with malicious content. The Chromium security severity is listed as Medium, indicating a notable risk to user trust and interaction but no direct evidence of code execution or system compromise. The flaw aligns with CWE-1021 and CWE-451 vulnerabilities.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 on all supported operating systems are affected. The issue is tied to the Downloads component of the browser.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 indicates a Medium severity. The likely attack vector is remote, with the attacker delivering a crafted HTML page via a web link or possibly email. No additional prerequisites such as local privileges are required, and exploitation can occur in the normal browsing mode.
OpenCVE Enrichment
Debian DSA