Impact
Google Chrome for Android rendered a crafted HTML page inside the Messages interface on versions before 149.0.7827.53, allowing a remote attacker to perform user interface spoofing. The flaw does not provide direct code execution but enables deceptive, phishing‑style interactions that can mislead users and compromise trust and privacy.
Affected Systems
The vulnerability affects all Chrome for Android devices running a version older than 149.0.7827.53. Users on the stable channel who have not yet upgraded remain susceptible.
Risk and Exploitability
The attack vector requires hosting a malicious HTML page that a user can visit through the Messages interface. The CVSS score of 8.8 categorizes it as high severity, and the EPSS score of < 1% indicates a low exploitation probability. Because it is not listed in the CISA KEV catalog, no large‑scale public exploits are known at this time, but the potential for deception warrants prompt mitigation.
OpenCVE Enrichment