Impact
Google Chrome before version 152.0.7977.65 contained a flaw that allowed a remote attacker to create a crafted HTML page which, when opened in the browser, caused the navigation UI to display a spoofed address bar. The misrepresentation can mislead users into believing the browser is visiting a different site than it actually is, potentially enabling phishing or social‑engineering attacks.
Affected Systems
All users running any version of Google Chrome prior to 152.0.7977.65 on any platform are affected, as the vulnerability is specific to the desktop browser’s navigation UI.
Risk and Exploitability
The exploitation requires the victim to visit a malicious web page, so it is a browser‑based attack that depends on user interaction. The CVSS score is 5.4, classified as medium, indicating that while the flaw does not allow arbitrary code execution, it can significantly undermine user trust in the browser’s interface and create an environment conducive to credential theft or other social‑engineering attacks. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment
Debian DLA
Debian DSA