Impact
The vulnerability is caused by insufficient validation of untrusted input in the Autofill component of Google Chrome on Android, allowing a remote attacker to perform UI spoofing through a crafted HTML page. This flaw enables counterfeit form elements to appear authentic, potentially tricking users into entering sensitive information into maliciously rendered fields. The primary weakness is improper input validation, classed as CWE-20.
Affected Systems
Google Chrome for Android versions prior to 150.0.7871.47 are affected. Users of these versions may encounter UI spoofing when visiting malicious web pages that exploit the Autofill component. Affected browsers can be mitigated by updating to the current release, which includes the necessary fix.
Risk and Exploitability
The CVSS score of 4.3 indicates modest severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the field. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely by delivering crafted content to a vulnerable viewer; no local privileges or device compromise are required.
OpenCVE Enrichment
Debian DLA
Debian DSA