Impact
An arbitrary incorrect handling in Chrome’s Views component lets a remote attacker create a malicious HTML page that displays user‑interface elements that do not match the page’s actual content. The flaw reflects CWE‑1021 and CWE‑451 weaknesses, and is used for UI spoofing, which can mislead a visitor into believing they are interacting with a different website or application than they truly are.
Affected Systems
Google Chrome browsers with versions older than 151.0.7922.72 on desktop platforms are susceptible. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity assessment, while the EPSS score of less than 1% points to a low current exploitation probability and the issue is not catalogued in the CISA KEV database. The attack can be delivered via a crafted web page loaded in Chrome, as described in the advisory. No additional exploitation conditions are reported.
OpenCVE Enrichment
Debian DLA
Debian DSA