Impact
The vulnerability is a UI misrepresentation flaw in the input handling of Google Chrome on macOS, discovered before version 152.0.7977.65. A malicious web page can provide crafted HTML that masquerades native UI controls, leading the user to believe they are interacting with legitimate browser prompts. This spoofing can be abused to trick users into providing credentials or sensitive information. Chromium categorised the issue as Medium severity. The flaw does not lead to code execution.
Affected Systems
Affected systems are Google Chrome users on macOS devices running any Chrome version before 152.0.7977.65. The vulnerability was fixed in subsequent releases, beginning with the stable channel update released in August 2026. No other vendors or product lines are impacted according to the available CNA data.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the KEV catalogue, indicating a low but non‑zero exploitation probability. The attack vector is inferred as a user loading a malicious HTML page that contains crafted input designed to mimic native UI controls. While the flaw does not provide code execution or privilege escalation, the spoofed UI can facilitate phishing or credential theft when a user interacts with the deceptive elements. The CVSS score of 5.4 indicates medium severity.
OpenCVE Enrichment
Debian DLA
Debian DSA