Impact
Google Chrome versions prior to 152.0.7977.65 contain a flaw in the geometry rendering engine that lets a remote attacker change the appearance of UI elements through a crafted HTML page. The vulnerability, evaluated with a CVSS score of 5.4, enables the browser to display altered or fabricated interface components without affecting underlying browser logic, potentially misleading users about the true state of a page.
Affected Systems
Affected systems are installations of Google Chrome on any platform where the browser version is older than 152.0.7977.65. The issue was fixed in the stable update 152.0.7977.65; no additional platform or configuration constraints were reported.
Risk and Exploitability
The CVSS score indicates moderate risk and the EPSS score of less than 1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a malicious web page that is served to an affected user; the attacker supplies crafted HTML that causes the browser to render UI elements that do not reflect the actual content of the page, possibly leading to user confusion.
OpenCVE Enrichment
Debian DLA
Debian DSA