Impact
The vulnerability originates from an inappropriate implementation in the Input subsystem of Google Chrome for Android. It allows a remote attacker to create a crafted HTML page that performs UI spoofing, thereby deceiving users into interacting with a counterfeit user interface. It is categorized as CWE‑451 and CWE‑79.
Affected Systems
This flaw affects Google Chrome on Android versions prior to 151.0.7922.72. Users running earlier builds are susceptible to the exploit until the patch is applied.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity, and the EPSS score of less than 1% suggests that exploitation is unlikely. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack requires a remote attacker to host a malicious web page that the victim must visit, and the exploit conditions are limited to the victim accessing the crafted page. No exploitation conditions beyond visiting the crafted page are noted.
OpenCVE Enrichment
Debian DLA
Debian DSA