Impact
The flaw occurs in the Views component of Google Chrome, where security UI elements are rendered incorrectly. This permits a remote attacker to host a crafted web page that encourages a user to perform specific UI gestures, after which the browser displays UI that appears legitimate but is actually fabricated, enabling UI spoofing. The weakness is a flaw in UI rendering control (CWE‑451).
Affected Systems
All desktop installations of Google Chrome prior to version 150.0.7871.47 that have not yet received the relevant update are potentially affected.
Risk and Exploitability
The CVSS score of 4.2 classifies this as low severity. The EPSS score is <1%, and the vulnerability is not listed in the CISA KEV catalog, indicating limited evidence of exploitation. The attack requires social–engineering; it is inferred that the attacker must persuade a user to visit the malicious page and perform the required gestures, after which the user may unknowingly interact with counterfeit security prompts.
OpenCVE Enrichment
Debian DLA
Debian DSA