Impact
A flaw in the Paint component of Google Chrome allows remote attackers to render user interface elements that look legitimate but are actually deceptive, enabling phishing or social‑engineering attacks. The vulnerability, classified as CWE‑451, leads to UI spoofing without granting arbitrary code execution. Attackers may trick users into submitting sensitive information by presenting forged interface elements.
Affected Systems
Vulnerable users are those running Google Chrome on desktop, stable channel, with any version earlier than 150.0.7871.47. Only the Paint feature is impacted; no other Chrome components are affected.
Risk and Exploitability
Chromium rates the issue as medium severity with a CVSS score of 4.3. The EPSS score is less than 1% and it is not listed in CISA’s KEV catalog. The likely attack vector is remote: a maliciously crafted HTML page must be loaded by the user, who then interacts with the spoofed UI, but the vulnerability does not allow code execution.
OpenCVE Enrichment
Debian DLA
Debian DSA