Impact
An improper FullScreen implementation in Google Chrome for Android allowed a remote attacker to craft an HTML page that could mimic the user interface, potentially misleading users into performing unintended actions. The vulnerability does not provide code execution or data exfiltration but can compromise user trust and induce phishing‑like deception.
Affected Systems
Google Chrome on Android browsers running versions prior to 151.0.7922.72 are affected. Users on the stable channel of Chrome that have not yet updated to this release are at risk.
Risk and Exploitability
With a CVSS score of 4.3 and an EPSS below 1%, the likelihood of widespread exploitation is low and the vulnerability is not listed in CISA’s KEV catalog. An attacker would need to serve a carefully crafted web page to a victim using Chrome on Android, and the impact is primarily UI deception rather than system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA