Impact
The flaw allows a malicious web page to present UI elements that mimic native browser components, thereby misleading users into believing the interface has been altered. By compromising the renderer process, an attacker can craft a page that visually resembles authentic UI controls, which can trick users into performing unintended actions. This vulnerability is classified as low severity, indicating limited practical damage without additional compromise.
Affected Systems
Google Chrome for macOS versions earlier than 152.0.7977.65 are affected. The issue resides in the Core UI module of the stable channel.
Risk and Exploitability
The EPSS score is < 1%, indicating very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.3 marks it as low severity, and exploitation requires the attacker to deliver malicious HTML that is rendered by a compromised renderer process. Therefore, risk is primarily tied to the presence of compromised renderer code and exposure to untrusted web content.
OpenCVE Enrichment
Debian DLA
Debian DSA