Impact
The vulnerability is an insufficient validation of untrusted network input in the Passwords component in Google Chrome. The flaw permits a remote attacker to send crafted traffic that causes the browser to render forged authentication dialogs or password prompts, allowing the attacker to trick users into divulging credentials. The weakness corresponds to CWE‑20 (Improper Input Validation) and includes a partial authorization bypass (CWE‑290).
Affected Systems
Affected browsers are Google Chrome versions earlier than 151.0.7922.72. Anyone using those releases on any platform is potentially exposed to UI spoofing attacks. The issue is specific to the Chrome browser and does not affect other Chrome‑derived browsers that have not yet applied this fix.
Risk and Exploitability
The CVSS score of 4.3 classifies this as low severity. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in CISA KEV. Exploitation requires a remote attacker to be able to deliver malicious network traffic to a browser session; based on the description, it is inferred that the attacker also needs to persuade the user to interact with the forged UI, which introduces a social‑engineering component. Given the low severity and limited exploitability, the overall risk is moderate but should still be addressed.
OpenCVE Enrichment
Debian DLA
Debian DSA