Impact
Inappropriate implementation of the Picture‑in‑Picture feature in Google Chrome allowed a remote attacker to persuade a user to perform specific interface gestures that result in UI spoofing. By loading a crafted HTML page, the attacker can overlay deceptive elements or misleading controls that trick the user into believing they are interacting with legitimate content. This flaw is classified as CWE‑451 and can lead to phishing or other social‑engineering attacks.
Affected Systems
The vulnerability affects Google Chrome versions older than 145.0.7632.45 on all major operating systems, including macOS, Linux, and Windows. As the Picture‑in‑Picture mode operates across platforms, the threat is applicable to every user running an impacted Chrome build regardless of OS.
Risk and Exploitability
Severity is medium with a CVSS score of 6.5 and an EPSS probability of less than 1 %, indicating a relatively low chance of exploitation at this time, and it is not listed in CISA’s KEV catalog. Exploitation requires a malicious web page that induces the user to perform UI gestures; the attack is user‑initiated and relies on social engineering. The most likely vector is a compromised or malicious website that prompts the user to engage with Picture‑in‑Picture controls.
OpenCVE Enrichment
Debian DSA