Impact
Insufficient validation of untrusted input in Google Chrome’s Password Manager allows a remote attacker to perform UI spoofing through malicious network traffic. The flaw permits manipulation of the user interface presented by the password manager, potentially tricking users into interacting with a forged prompt. This weakness is classified as CWE-1021 and CWE-20.
Affected Systems
Google Chrome browsers earlier than version 149.0.7827.53 on any operating system are affected, because the vulnerability resides in the cross‑platform password manager component.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote via malicious network traffic, meaning that a compromised website or network element can deliver the spoofed UI elements. Based on the description that the UI can be spoofed, it is inferred that a user may inadvertently enter credentials into a malicious prompt, potentially exposing sensitive data. The Chromium severity is Medium, with a CVSS score of 4.3, indicating a non‑critical but still actionable flaw.
OpenCVE Enrichment
Debian DSA