Impact
Google Chrome prior to 152.0.7977.75 has a UI misrepresentation flaw that becomes active when a page is displayed in full-screen mode. A malicious web page can cause the Chrome address bar to show a forged URL, allowing a remote attacker to deceive a user into believing they are viewing a different site. The weakness corresponds to CWE‑451 and results in information disclosure by misrepresenting the page’s identity, potentially enabling phishing or social engineering attacks. No data execution or server compromise is possible from the flaw alone.
Affected Systems
The vulnerability affects the stable channel of Google Chrome browsers running any operating system, specifically versions older than 152.0.7977.75. Any installation of Chrome before that version is susceptible when it renders a page in full‑screen mode.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. The CVE severity is marked low, and the attack requires a remote attacker to host a crafted HTML page that a user visits while the browser is in full‑screen mode. Because the flaw does not grant code execution or privileged access, the overall risk is moderate, primarily arising from social engineering.
OpenCVE Enrichment