Impact
The flaw arises from improper handling of password prompts in Chrome versions before 150.0.7871.47, enabling a malicious page to present a UI that looks like the browser’s native password prompt. The CVE report states that this UI spoofing could allow credential theft. The weakness is classified as CWE‑451, reflecting information exposure from inadequate processing of untrusted input. Though the description does not describe the exact mechanism, the apparent consequence is that a user entering credentials into the false prompt may have those details exposed to the attacker.
Affected Systems
Google Chrome binaries prior to 150.0.7871.47 on any platform are affected. All installations of those releases are potentially vulnerable.
Risk and Exploitability
Based on the description, it is inferred that the attacker uses a crafted HTML page to display the spoofed dialog. The CVSS score of 4.3 indicates medium severity, while the EPSS score of < 1% indicates a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. This likely phishing or social‑engineering scenario requires a user to visit the malicious page and interact with the false prompt, allowing credential theft. Though exploitation probability is low, credential compromise remains a real risk.
OpenCVE Enrichment
Debian DLA
Debian DSA