Impact
The flaw arises from improper handling of password prompts in Chrome versions before 150.0.7871.47, enabling a malicious page to present a UI that looks like the browser’s native password prompt. The CVE report states that this UI spoofing could allow credential theft. The weakness is classified as CWE‑451, reflecting information exposure from inadequate processing of untrusted input. Though the description does not describe the exact mechanism, the apparent consequence is that a user entering credentials into the false prompt may have those details exposed to the attacker.
Affected Systems
Google Chrome binaries prior to 150.0.7871.47 on any platform are affected. All installations of those releases are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 indicates medium of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The attack requires a user to visit a crafted web page that displays the spoofed dialog, implying a phishing or social‑engineering scenario. While exploitation likelihood is low, the potential for credential compromise remains real.
OpenCVE Enrichment
Debian DLA
Debian DSA