Impact
Incorrect security UI in Chrome Extensions on Android before version 150.0.7871.47 allows a remote attacker to craft an HTML page that convinces a user to perform specific gestures, enabling the attacker to spoof the UI. This flaw can deceive a user into interacting with a fake interface, potentially leading to social engineering or other malicious actions. The impact is a user interface deception vulnerability, classified with medium severity in Chromium’s internal security rating.
Affected Systems
Google Chrome for Android, versions prior to 150.0.7871.47 are affected.
Risk and Exploitability
The exploit requires a crafted HTML page that presents misleading UI elements, and the attacker must convince a user to engage with particular UI gestures. Because the flaw is limited to the UI layer, it does not provide direct code execution, but it elevates the risk of phishing attacks. The EPSS score is <1%, indicating a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. The medium severity still warrants prompt remediation through an update to a fixed Chrome version, as the vulnerability can be triggered by a remote web page exposed to the user.
OpenCVE Enrichment
Debian DLA
Debian DSA