Impact
The vulnerability is a UI misrepresentation in Web Authentication (Passkeys & Security Keys) that existed in Google Chrome before version 152.0.7977.65. A crafted HTML page can trick the user into performing an authentication action that bypasses system access restrictions, effectively allowing remote exploitation through social engineering. The weakness corresponds to CWE‑451, reflecting a misleading user interface. The impact is unauthorized system access, potentially compromising confidentiality and integrity of the affected machine by permitting a user to log in or authenticate without proper verification.
Affected Systems
Google Chrome, all releases prior to 152.0.7977.65. The vulnerability was identified in the stable channel of Chrome on desktop.
Risk and Exploitability
CVSS score is 6.5, and the EPSS score is less than 1%. The vulnerability is not listed in CISA KEV. Exploitation requires a crafted web page and social engineering, so the risk is limited to users who visit malicious sites. Because the vulnerability allows a user to bypass authentication, a patch is advised even though exploitation conditions remain user‑dependent.
OpenCVE Enrichment
Debian DLA
Debian DSA