Impact
A flaw in how Google Chrome renders and represents the user interface of extensions allows a remote attacker to use social engineering to trick a user into installing a crafted extension, which can then access sensitive data. The vulnerability corresponds to CWE-451, representing a misrepresentation that can lead to unintended user actions. The direct effect is the potential for confidential data to be disclosed to an attacker.
Affected Systems
Google Chrome browsers version 152.0.7977.64 and earlier are affected. The issue is tied to the Chrome UI handling of extensions prior to the 152.0.7977.65 release. Users on any platform running the vulnerable Chrome version are susceptible if they install or use a malicious extension crafted by an attacker.
Risk and Exploitability
Chromium rates the vulnerability as Medium severity, with a CVSS score of 6.5. Exploitation relies on a user accepting a malicious extension, which requires a social‑engineering attack. The EPSS score is reported as less than 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. Nevertheless, the widespread usage of Chrome and the ubiquity of extensions mean that the risk remains significant for users who do not regularly update their browsers or scrutinize extension permissions.
OpenCVE Enrichment
Debian DLA
Debian DSA