Impact
Inappropriate handling of password input fields in Google Chrome versions before 149.0.7827.53 allows a remote attacker to craft a malicious web page that visually mimics the genuine login UI. This flaw enables the attacker to trick a user into believing they are interacting with a legitimate site and consequently submitting sensitive credentials. The vulnerability does not grant code execution or system compromise; it solely facilitates a deceptive user‑interface for credential theft.
Affected Systems
All users running Google Chrome prior to version 149.0.7827.53 are affected. The issue applies to the stable channel on all desktop operating systems where the browser is installed.
Risk and Exploitability
The vulnerability is classified as Low in Chromium’s severity matrix. Exploitation requires user interaction with a specially crafted page that will be rendered by Chrome. No publicly known exploit exists, the EPSS score is unavailable, and the flaw is not listed in CISA’s KEV catalog, indicating limited known exploitation activity. Nevertheless, because the attack can lead to credential compromise, system administrators should treat the flaw as a potential threat condition until the recommended update is applied.
OpenCVE Enrichment