Impact
The vulnerability arises from an inappropriate implementation in Google Chrome’s password interface. An attacker could send malicious network traffic that tricks the browser into presenting a fake credential entry prompt. This UI spoofing can lead a user to enter sensitive information into a deceptive interface, matching the characteristics of CWE-1021 (Improper Verification of Resource Ownership) and CWE-451 (Improper Handling of Dynamic Content).
Affected Systems
Affected products include Google Chrome on desktop operating systems (Windows, macOS, and Linux) running the stable channel builds older than 151.0.7922.72. Users who rely on Chrome’s integrated password manager in those builds are potentially vulnerable.
Risk and Exploitability
The CVSS score of 4.3 classifies this as low severity, and the EPSS score indicates a probability of exploitation of less than 1%. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation has been observed. The likely attack vector is remote: an adversary can use specially crafted traffic to trigger the spoofed prompt. The risk is confined to situations where the user interacts with the manipulated interface and could facilitate credential theft through phishing.
OpenCVE Enrichment
Debian DLA
Debian DSA