Impact
Google Chrome on Windows has a flaw in the Autofill security UI that allows a remote attacker to craft an HTML page which, when a user interacts with it, displays a spoofed interface. This manipulation can lead the user to submit gestures or data believing the UI is legitimate, thereby exposing sensitive information or enabling credential theft. The vulnerability is a medium severity issue reported by Chromium.
Affected Systems
Versions of Google Chrome for Windows earlier than 150.0.7871.47 are affected.
Risk and Exploitability
Because the exploit requires a crafted web page and active user participation, the likelihood of a widespread attack is limited, yet it remains possible in targeted phishing campaigns. No EPSS value is available and the vulnerability is not listed in the CISA KEV catalog. The current medium severity reflects the potential for deception but not for arbitrary code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA