Impact
A flaw in Google Chrome’s handling of password prompts allows a remote attacker who has already compromised the renderer process to deliver a spoofed password UI through a crafted HTML page. Because the attacker can masquerade the browser’s security dialog, a user may unknowingly enter credentials or other sensitive data into a fake prompt. This vulnerability is classified as CWE‑451, reflecting a broken UI‑security boundary.
Affected Systems
All Google Chrome installations built before version 150.0.7871.47 on any supported operating system are affected. The issue is confined to the renderer process that displays password interfaces.
Risk and Exploitability
Exploiting this flaw requires a prior compromise of the renderer process, typically via malicious content or another vulnerability. The CVSS score of 3.1 indicates a low severity, and an EPSS score of less than 1% shows a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, suggesting no known active exploits yet. Nevertheless, if an attacker can subvert renderer code, the spoofed password prompt could be used for phishing attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA