Impact
Chrome’s DarkMode feature contains a render‑time flaw that lets a remote attacker craft a web page with elements that mimic native browser controls. The flaw, identified as CWE‑1021 and CWE‑451, does not grant code execution or credential theft but can deceive users into interacting with counterfeit UI components.
Affected Systems
All versions of Google Chrome older than 150.0.7871.47 are affected. Updating to the 150.0.7871.47 stable release removes the vulnerable rendering path.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as low severity, and an EPSS score of less than 1% indicates a very low probability of exploitation. The exploit requires a victim to visit a malicious page, after which the spoofed UI is displayed. While no public exploits are reported and the vulnerability is not listed in CISA’s KEV catalog, the risk remains non‑zero because an attacker could use social engineering to present the counterfeit controls to a user.
OpenCVE Enrichment
Debian DLA
Debian DSA