Impact
The flaw is an incorrect security UI in Google Chrome for Android that allows a remote attacker to create a crafted HTML page presenting a forged interface that appears legitimate. This weakness is identified as CWE‑451. The description does not mention code execution; based on the description, it does not provide a direct method for arbitrary code execution.
Affected Systems
All installations of Google Chrome for Android running a version earlier than 150.0.7871.47 are affected.
Risk and Exploitability
Chromium rates the flaw as Medium severity, reflected by a CVSS score of 4.3. The EPSS score is less than 1%, and it is not listed in the CISA KEV catalog. The likely attack vector is a malicious web page that serves the crafted UI, an inference drawn from the description. Exploitation would require a user to view the page; no additional privileges are needed.
OpenCVE Enrichment
Debian DLA
Debian DSA