Impact
Google Chrome versions before 148.0.7778.96 contain a weakness where the WebApp component does not enforce its security policy strictly. This flaw enables a malicious web page to forge user interface elements, misleading users into interacting with fake controls or entering sensitive data. The attack does not give code execution privileges, but it can lead to social engineering and data theft by convincing users that they are interacting with legitimate Chrome UI.
Affected Systems
The affected product is Google Chrome. All desktop installations running any version prior to 148.0.7778.96 are vulnerable; the flaw was present in stable channel releases before that version. No other vendors or products are listed.
Risk and Exploitability
The CVSS score is 5.4, indicating a moderate risk level. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. A remote attacker can exploit the flaw by hosting a crafted HTML document and tricking a user into opening or interacting with it in a Chrome browser. The likelihood of exploitation is limited by the need for user interaction, but the impact could be significant if users provide sensitive information to the spoofed UI.
OpenCVE Enrichment
Debian DSA