Impact
In Google Chrome for Android versions below 150.0.7871.47, an inappropriate implementation in SiteSettings allows a remote attacker to perform UI spoofing through a crafted HTML page. The vulnerability is classified as CWE-451, indicating that a malicious website can alter the browser’s user interface to create a deceptive experience for the user. The impact is primarily user deception rather than direct data compromise, as the attacker can modify how the browser presents itself without gaining code execution or data access.
Affected Systems
All installations of Google Chrome on Android running a release older than 150.0.7871.47 are affected. The issue is limited to the Android rendering of Chrome’s SiteSettings and does not systems.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity level, while the EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, suggesting a low likelihood a malicious website that serves a crafted HTML page; no additional exploitation is required, and the impact is primarily user deception rather than direct data compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA