Impact
An inappropriate implementation in the Messages component of Google Chrome for Android allows a remote attacker to persuade users that a maliciously crafted HTML page is part of the legitimate browser UI. The flaw, classified as CWE-1021 and CWE-451, permits UI spoofing that can deceive users into divulging credentials or engaging with content that compromises confidentiality or integrity. The impact is limited to deception and social engineering rather than direct code execution.
Affected Systems
This vulnerability affects Google Chrome for Android versions before 151.0.7922.72. Users who have not upgraded to the latest stable release, 151.0.7922.72 or newer, are at risk.
Risk and Exploitability
The CVSS score of 6.5 reflects a medium severity, and the EPSS score of less than 1% indicates a very low probability of exploitation in the current environment. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote, crafted HTML page that the user must load in the browser, making widespread exploitation difficult but still possible if users visit malicious sites.
OpenCVE Enrichment
Debian DLA
Debian DSA