Impact
A vulnerability in Google Chrome’s WebAppInstalls feature before version 152.0.7977.65 allows a remote attacker to create a crafted HTML page that causes the browser to display UI elements that do not reflect the underlying content. This misrepresentation can trick users into interacting with elements that appear legitimate, potentially leading to unintended actions such as granting permissions or initiating downloads. The weakness is categorized as CWE-451, reflecting incorrect generation of user‑facing content that can mislead users.
Affected Systems
Google’s Chrome browser, specifically any release prior to 152.0.7977.65. All users running those versions are susceptible when they load an attacker‑controlled WebAppInstalls page.
Risk and Exploitability
The vulnerability is reachable from a standard web page, meaning any site can host the malicious page. The CVSS score is 5.4, indicating a medium level impact, and the EPSS score is < 1%, showing a low likelihood of exploitation. The incident has not been listed in the CISA KEV catalog. An attacker would need only to entice a user to visit a malicious site; no privileged access or additional system credentials are required. The risk is therefore moderate, with a moderate likelihood of exploitation in environments that load WebAppInstalls pages from untrusted origins.
OpenCVE Enrichment
Debian DLA
Debian DSA