Impact
A remote attacker can manipulate the Omnibox user interface in Google Chrome to display misleading elements, causing users to interact with content that they believe is part of the legitimate browser UI. The flaw stems from an incorrect rendering of the security UI when a crafted HTML page is loaded. This issue reflects the weaknesses identified by CWE‑451 and CWE‑20. Chromium classifies this issue as low severity because it does not allow code execution or direct system compromise.
Affected Systems
Google Chrome browsers older than version 150.0.7871.47 are vulnerable. The vulnerability is triggered when a malicious web page is opened in the affected Chromium installation. Based on the description, it is inferred that the flaw affects all supported Chrome platforms, as it resides in the common Omnibox component.
Risk and Exploitability
The CVSS score of 4.3 classifies the vulnerability as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, suggesting no publicly reported exploits. Exploitation requires the victim to navigate to a crafted HTML page, making the attack dependent on user action rather than automated vectors. Given the low exploitation likelihood, the overall risk remains low, though the UI spoofing can undermine user trust.
OpenCVE Enrichment
Debian DLA
Debian DSA