Impact
An attacker can load a specially crafted web page and use the Transactions Platform in Google Chrome to misuse how user interface elements are displayed. The vulnerability allows the UI to be misrepresented, enabling a malicious page to forge or alter transaction prompts and other graphics that a user trusts, which can be leveraged for social‑engineering attacks. The flaw does not permit execution of arbitrary code but can lead to the user making unintended actions or revealing sensitive information. The weakness is a form of untrusted input without proper validity checks.
Affected Systems
All users of Google Chrome with a version earlier than 152.0.7977.65 are affected. The flaw exists in the Transactions Platform component of the browser and affects all installations where that component is active.
Risk and Exploitability
The EPSS score of < 1% indicates a very low exploitation probability, and the CVSS score of 4.3 confirms low severity. Because the flaw relies on a user interacting with a malicious web page, exploitation requires social engineering and user action. The Chromium security severity is rated low, indicating that the impact is limited to UI deception and potential phishing rather than direct code execution or system compromise. As no publicly disclosed exploits are known and the risk is contingent on user interaction, the overall likelihood of exploitation is considered low, though vigilance is still warranted.
OpenCVE Enrichment
Debian DLA
Debian DSA