Impact
An inappropriate implementation of permissions in Google Chrome versions before 149.0.7827.53 allows a remote attacker to perform UI spoofing through a crafted HTML page. The flaw causes the browser to render counterfeit permission prompts that appear to be legitimate Chrome dialogs. While the vulnerability does not enable direct data theft or code execution, it can deceive users into granting permissions or revealing sensitive information, thereby undermining user trust and enabling social engineering.
Affected Systems
All desktop builds of Google Chrome older than version 149.0.7827.53 are affected, regardless of the operating system. The flaw applies to every release prior to that specific version.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and an EPSS score of < 1% suggests a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that a malicious web page must be served to the victim’s browser to trigger the attack, meaning the attack can be carried out remotely over the network. The lack of direct exploitation capabilities limits the damage to user deception rather than system compromise.
OpenCVE Enrichment
Debian DSA