Impact
A remote attacker can manipulate the Omnibox user interface in Google Chrome to display misleading elements, causing users to interact with content that they believe is part of the legitimate browser UI. The flaw stems from an incorrect rendering of the security UI when a crafted HTML page is loaded. This issue reflects the weakness identified by CWE-451. Chromium classifies this issue as low severity because it does not allow code execution or direct system compromise.
Affected Systems
Google Chrome browsers older than version 150.0.7871.47 are vulnerable. The susceptibility applies when a malicious web page is opened in the affected Chromium installation. The flaw affects all platforms that Chrome runs on, including Windows, macOS, and Linux.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly reported exploits. Exploitation requires the victim to navigate to a crafted HTML page, making the attack dependent on user action rather than automated vectors. Given the low exploitation likelihood, the overall risk remains low, though the UI spoofing can undermine user trust.
OpenCVE Enrichment
Debian DLA
Debian DSA