Impact
A remote attacker can craft an HTML page that deceives a user into interacting with a user interface that appears legitimate, enabling phishing or credential disclosure. The flaw resides in how Permissions are handled in Google Chrome, resulting in UI elements being spoofed. The issue is classified as low severity, indicating that the vulnerability poses primarily a deception risk rather than direct system compromise.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53 on all operating systems supported by Chrome are affected. The vulnerability is present in the Desktop channel and any other channel that has not yet received the 149.0.7827.53 update.
Risk and Exploitability
Exploitation only requires the attacker to serve a malicious web page to the victim; no elevated privileges or credentials are needed. Once the victim visits the crafted page, the spoofing can be executed. The CVSS score of 4.3 reflects a low severity rating, and the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting that large‑scale exploitation is unlikely at present. Attackers would generally rely on social engineering or drive‑by‑download tactics to lure users to the malicious page.
OpenCVE Enrichment