Impact
An incorrect security UI in WebAppInstalls in Google Chrome versions prior to 150.0.7871.47 allows a remote attacker who convinces a user to perform specific gestures in the browser to cause the UI to display a spoofed device security warning for a domain that does not match the page’s real origin. The attacker can deliver a crafted HTML page that tricks the user into thinking they are interacting with a legitimate site, potentially leading to phishing or credential theft. The flaw is an emulation of a domain, not a code execution or authentication bypass, and is rated medium severity by Chromium.
Affected Systems
The vulnerability affects unpatched desktop installations of Google Chrome older than version 150.0.7871.47. Those builds present the incorrect UI during WebAppInstalls, exposing users to crafted HTML pages that may trigger the exploit.
Risk and Exploitability
The CVSS score is 4.2, indicating a medium severity. EPSS data is not available and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a victim to perform specific, user‑initiated gestures prompted by a malicious web page, meaning the risk is greatest in the context of social engineering or phishing attacks. No publicly known workaround exists beyond avoiding the risky UI interactions.
OpenCVE Enrichment
Debian DLA
Debian DSA