Impact
Insufficient validation of untrusted input in Google Chrome Wallet prior to version 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. The weakness is a form of CWE‑20 "Improper Input Validation" and CWE‑79 "Cross‑Site Scripting" and could make users interact with fraudulent wallet interfaces, potentially exposing sensitive data or enabling transaction manipulation.
Affected Systems
Google Chrome desktop versions earlier than 149.0.7827.53 are affected.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, rated low by Chromium’s security team, and is not listed in the CISA KEV catalog. The EPSS score is < 1%, indicating a very low probability of exploitation, especially since it requires prior compromise of the renderer process. Nonetheless, the potential for user deception exists, and updating Chrome mitigates the risk.
OpenCVE Enrichment
Debian DSA