Impact
An inappropriate implementation of the PreviewTab feature in Google Chrome for Android allows a remote attacker, through specific on‑screen gestures, to cause the browser to render a crafted HTML page that masquerades as a legitimate user interface. The victim sees counterfeit UI elements appearing within the browser, and this UI spoofing could mislead the user into interacting with malicious content. The vulnerability is identified as CWE‑451 and is rated low severity.
Affected Systems
Google Chrome for Android versions earlier than 150.0.7871.47, specifically the PreviewTab component, are affected.
Risk and Exploitability
The CVSS score of 4.2 places this issue in the low‑severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. Because the vulnerability is absent from the CISA KEV catalog and requires explicit user interaction with precise UI gestures, the likelihood of successful attacks remains low, limiting overall risk.
OpenCVE Enrichment
Debian DLA
Debian DSA