Impact
Google Chrome DevTools contains insufficient policy enforcement that permits a malicious extension to perform UI spoofing if a user is convinced to install it. The crafted extension can manipulate the appearance of DevTools, potentially deceiving users into interacting with a falsified interface. This vulnerability arises from a lack of strict policy controls (CWE‑280) and the failure to review untrusted content injected by extensions (CWE‑451), allowing extensions to alter the UI without proper permissions checks. Chromium classifies this flaw as low severity, indicating that its impact is confined to user deception rather than direct data compromise or system takeover.
Affected Systems
Any installation of Google Chrome before version 148.0.7778.96 is affected. All earlier stable releases can be exploited if an attacker achieves installation of a malicious extension.
Risk and Exploitability
The CVE is not listed in CISA’s KEV catalog, indicating limited public information about exploitation. The EPSS score of < 1% suggests a very low likelihood of exploitation in the current threat environment. The likely attack vector is social engineering that results in the user installing a malicious extension. An attacker does not need network privileges or remote access; the vulnerability is limited to the user’s browser session and the DevTools UI. Given the low severity rating, the overall risk to sensitive data or system integrity is minimal, although deceptive interfaces could lead to phishing or credential theft. The CVSS score for this vulnerability is 5.4.
OpenCVE Enrichment
Debian DSA