Impact
An incorrect security user interface in Google Chrome for Android versions before 150.0.7871.47 allows a remote attacker to serve a specially crafted HTML page that displays a forged domain in the address bar. The manipulation deceives users into believing they are visiting a legitimate site, potentially leading to phishing or social engineering attacks. This flaw is classified as CWE-451.
Affected Systems
Google Chrome on Android devices running any release build prior to version 150.0.7871.47. The vulnerability applies to all releases of Chrome available on Android where the unsafe UI path is present.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1 percent suggests a low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Based on the description, it is inferred that a remote attacker must host or deliver a crafted HTML page to the victim’s browser; no local privileges or administrative rights are required. Any user who opens the malformed page in Chrome is potentially impacted.
OpenCVE Enrichment
Debian DLA
Debian DSA