Impact
Google Chrome’s DarkMode implementation contains an error that permits a remote attacker to craft an HTML page that displays UI elements mimicking native browser controls. The vulnerability, classified as CWE-451, allows the spoofed UI to appear as genuine Chrome components once a user navigates to the malicious page, potentially leading the user to interact with deceptive controls. Based on the description, the attack vector is inferred to be a client‑side exploit where an attacker hosts a crafted web page and lures a victim to open it in Chrome. Since the effect relies on rendering the page in the browser, no remote code execution or credential Theft occurs; however, social engineering could lead to further compromise. The CVSS score of 4.3 indicates a low‑severity issue, and the EPSS score of <1% suggests exploitation is rare. The vulnerability is not listed in CISA’s KEV catalog, and no public exploits have been reported, but the risk remains low yet non‑zero because a motivated attacker could still deceive users into interacting with spoofed UI elements.
Affected Systems
All Google Chrome installations before version 150.0.7871.47 are affected. The Chrome stable channel update to 150.0.7871.47 removes the flaw, so systems running older builds must update to the latest release to eliminate the vulnerable rendering path.
Risk and Exploitability
With a CVSS of 4.3 the issue is considered low severity, and an EPSS of <1% indicates a low probability of exploitation. Because the flaw is limited to client‑side rendering and requires the victim to load a malicious page, the overall risk is low but not negligible. The vulnerability is not appended to CISA’s KEV catalog. An attacker would need to entice the victim to visit a crafted web page; once the page loads, the spoofed UI can be displayed, potentially misguiding user actions. Applying the patch or disabling the vulnerable feature provides definitive mitigation.
OpenCVE Enrichment
Debian DLA
Debian DSA