Impact
Missing authorization in the password handling flow of Google Chrome allowed a remote attacker who had already compromised the renderer process to spoof user interface elements via a crafted HTML page. This flaw enables an attacker to display counterfeit controls or prompts, potentially tricking users into revealing sensitive information. The weakness is a classic authorization bypass, classified as CWE‑862.
Affected Systems
Google Chrome on desktop platforms is vulnerable until the patch that addresses the flaw is installed.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity exploitation potential. The EPSS score of 0.00232 (<1%) indicates a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog, indicating that it is not yet widely exploited. The attack requires the attacker to compromise the renderer process, which typically implies local or remote code execution context within the browser. Because the flaw is high severity, attackers may simply use the compromised renderer to perform phishing or UI deception after establishing control over the browser environment.
OpenCVE Enrichment
Debian DLA
Debian DSA