Impact
An inappropriate implementation in Google Chrome’s Payments component before version 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. The flaw involves improper control and disclosure mechanisms, identified as CWE-1021 and CWE-451, and can cause the interface presented to a user during payment interactions to be manipulated, thereby altering the user experience.
Affected Systems
All Google Chrome desktop browsers on the stable channel with versions earlier than 149.0.7827.53 are vulnerable. Users who have not upgraded remain at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of < 1% suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to host a malicious HTML page that interacts with the Payments component; a user who visits this page could experience the spoofed interface.
OpenCVE Enrichment
Debian DSA