Impact
A defect in the Paint component of Google Chrome allows a remote attacker to render user interface elements that appear legitimate but are deceptive. This flaw, classified as CWE‑451, can enable phishing or social‑engineering attacks by persuading users to trust bogus UI elements.
Affected Systems
The vulnerability affects all installations of Google Chrome with any version earlier than 150.0.7871.47. Only the Paint feature is implicated; other Chrome components are not impacted.
Risk and Exploitability
Chromium assigns a CVSS score of 4.3. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog. Attackers need to serve a crafted HTML page to a user, who must then load and interact with it for the spoofing to occur. No elevated privileges or code execution are required, but the deception can lead to the disclosure of sensitive information.
OpenCVE Enrichment
Debian DLA
Debian DSA