Impact
The flaw is a UI misrepresentation that lets a remote attacker introduce a crafted HTML page to deceive users into interacting with spoofed interface elements. The remote attacker can manipulate the visual appearance of UI components, potentially tricking users into performing unintended actions or revealing sensitive information. This weakness is classified under CWE‑451.
Affected Systems
Google Chrome versions earlier than 152.0.7977.65 on desktop platforms are affected. The issue affects the stable channel and any users who have not applied the current patch.
Risk and Exploitability
The CVSS score of 4.3 indicates a low severity vulnerability. The EPSS score is less than 1%, and the flaw is not listed in the CISA KEV catalog. The attack requires a malicious web page and a social‑engineering vector; a remote attacker can load a crafted page to spoof UI elements and trick users into interacting with deceptive interface components.
OpenCVE Enrichment
Debian DLA
Debian DSA