Impact
Inappropriate implementation in Skia, the 2D graphics library used by Google Chrome, allows a remote attacker who has already compromised the renderer process to perform UI spoofing via a crafted HTML page. The flaw is identified as CWE‑451 and would let the attacker manipulate the browser’s display to deceive users into interacting with a malicious interface.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 on any supported platform are affected. The issue exists only in the Skia rendering component, so only the Chrome binaries that include the older Skia code are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS of less than 1 % indicate that the overall risk is low. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited exploitation activity. However, an attacker must first compromise the renderer process, which requires a separate compromise step. This means that while the attack vector is limited, it is technically possible for a compromised site or malicious content to trigger UI spoofing once the renderer has been subverted.
OpenCVE Enrichment
Debian DLA
Debian DSA