Impact
A flaw in Chrome’s Tab Hover Card security UI lets a maliciously crafted domain name appear legitimate, enabling an attacker to make a user believe the site is authentic. This misrepresentation can lead to phishing or other social engineering attacks, as users may trust content based on the displayed domain.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are susceptible; all later releases include the fix.
Risk and Exploitability
The vulnerability is considered low severity by Chromium, is not listed in the CISA KEV catalog, and has no reported EPSS score. Exploitation requires only that an attacker craft a domain that appears in the hover card, a remote‑only action that can be performed without local access.
OpenCVE Enrichment