Impact
An attacker who has compromised the renderer process can supply crafted HTML that is insufficiently validated in Chrome’s password handling path, allowing the attacker to present a deceptive login interface. This flaw is fundamentally an input validation issue (CWE‑20) that can be used to inject malicious content (CWE‑79) and trick users into divulging credentials. The immediate consequence is that any user interacting with the compromised page may be led to input sensitive data into counterfeit fields, creating a direct loss of confidentiality.
Affected Systems
Google Chrome versions earlier than 151.0.7922.72 are affected. The vulnerability exists in the default web‑content rendering engine used for password prompts in these releases. Users running those pre‑151 releases are at risk; upgrading beyond this version removes the defect.
Risk and Exploitability
The CVSS score of 6.5 marks this as a moderate severity issue, and the EPSS score of less than 1% indicates that exploit activity is expected to be rare. The flaw is currently not listed in the CISA KEV catalog, suggesting that widespread exploitation has not been observed. However, the vulnerability requires an attacker to first compromise the renderer process. Once that condition is met, the attacker can perform UI spoofing via a crafted page, leading to credential compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA