Impact
A browser UI misrepresentation flaw in Google Chrome versions prior to 152.0.7977.65 enables a remote attacker to spoof UI elements by delivering a specially crafted HTML page. The attacker can manipulate the appearance of web page controls or interface components, potentially leading to user confusion or manipulation. The vulnerability is classified as medium severity in Chromium’s internal assessment.
Affected Systems
Google Chrome, all users running versions earlier than 152.0.7977.65—including stable channel releases. Users on any other Chrome channel or version newer than 152.0.7977.65 are not affected.
Risk and Exploitability
The EPSS score is < 1% and the vulnerability is not listed in CISA KEV. The flaw is exploitable remotely through a malicious web page; an attacker controlling a web page can trigger the UI misrepresentation with no user interaction beyond visiting the page. Because the flaw allows arbitrary UI spoofing, an attacker could deceive users into performing unintended actions. The CVSS score of 5.4 indicates medium severity. The risk remains medium, but the very low EPSS score indicates that exploitation is unlikely at present.
OpenCVE Enrichment
Debian DLA
Debian DSA