Impact
Insufficient validation of untrusted input within the Input component of Google Chrome on Android allows an attacker to deliver a crafted HTML page that modifies the UI. The resulting UI spoofing can deceive users into interacting with deceptive elements, and based on the description it is inferred that this could enable phishing or other social‑engineering attacks. The weakness is a classic input validation flaw (CWE‑20).
Affected Systems
Google Chrome for Android releases prior to version 150.0.7871.47 are affected. Users running those versions are vulnerable until they upgrade to the patched build.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The most likely attack vector is remote: a malicious web page containing crafted HTML must be viewed by a victim, with no additional privileges or device compromise required.
OpenCVE Enrichment
Debian DLA
Debian DSA