Impact
A flaw in the PDF implementation of Google Chrome versions prior to 149.0.7827.53 allows an attacker who has already compromised the renderer process to deliver a crafted HTML page that can spoof the user interface. The weakness originates from inadequate input validation and can lead to deceptive UI overlays, potentially misleading users into performing unintended actions.
Affected Systems
Google Chrome browsers of any operating system version earlier than 149.0.7827.53 are affected. The vulnerability is tied to the PDF rendering component present in all standard Chrome releases.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall severity, and the EPSS score of less than 1% reflects a very low likelihood of exploitation. The vulnerability is also not listed in CISA’s KEV catalog. Exploitation requires that an attacker first compromise the renderer process; after gaining that control, the attacker can trigger a malicious HTML page that performs UI‑spoofing. Based on the description, this prerequisite limits the typical attack surface, so the overall risk to end users remains low, though it can still undermine user trust in contexts where UI authenticity is critical.
OpenCVE Enrichment
Debian DSA