Impact
An incorrect security user interface in Google Chrome for Android prior to version 150.0.7871.47 allows a remote attacker to serve a specially crafted HTML page that displays a forged domain name. This manipulation can deceive users into believing they are visiting a legitimate site, creating a risk of phishing or social engineering attacks. The flaw is classified as CWE-451.
Affected Systems
Google Chrome installed on Android devices running any release build before 150.0.7871.47. The vulnerability applies to all channel releases, including stable, that have not yet incorporated the patch.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1 percent suggests a low likelihood of exploitation. It is not listed in CISA’s KEV catalog. Exploitation requires a remote attacker to host or deliver a crafted HTML page to the victim’s browser; no local privileges or administrative rights are needed. Any user who opens the malicious page in Chrome is potentially impacted.
OpenCVE Enrichment
Debian DLA
Debian DSA