Impact
Inappropriate implementation in the Media UI of Google Chrome on ChromeOS allows a remote attacker, after persuading a user to perform specific UI gestures, to perform UI spoofing through a crafted HTML page. The flaw can trick users into interacting with counterfeit or malicious UI components and thus supports phishing or social‑engineering attacks. It does not provide code execution or privilege escalation, but it compromises interface integrity.
Affected Systems
Chrome on ChromeOS prior to version 150.0.7871.47 is affected. Updating to that version or later removes the flaw; no other platforms are listed as impacted.
Risk and Exploitability
Chromium classifies the issue as Medium severity with a CVSS score of 4.2. EPSS data is not available and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remote attacker hosting a crafted HTML page and convincing a user to perform the specific gestures, so user interaction is a prerequisite. Because of this intent‑driven requirement, the overall risk is low to moderate, though it can be leveraged for targeted social‑engineering attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA