Impact
Google Chrome prior to 152.0.7977.75 has a UI misrepresentation flaw that becomes active when a page is displayed in full‑screen mode. Based on the description, it is inferred that the attack vector is a malicious web page that a user visits while Chrome is in full‑screen mode. A malicious web page can cause the Chrome address bar to show a forged URL, allowing a remote attacker to deceive a user into believing they are viewing a different site. The weakness corresponds to CWE‑451 and results in information disclosure by misrepresenting the page’s identity, potentially enabling phishing or social engineering attacks. No data execution or server compromise is possible from the flaw alone.
Affected Systems
The vulnerability affects the stable channel of Google Chrome browsers running any operating system, specifically versions older than 152.0.7977.75. Any installation of Chrome before that version is susceptible when it renders a page in full‑screen mode.
Risk and Exploitability
The EPSS score is <1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. The CVSS score is 4.3, reflecting a low‑to‑moderate severity; the attack requires a remote attacker to host a crafted HTML page that a user visits while the browser is in full‑screen mode. Because the flaw does not grant code execution or privileged access, the overall risk remains moderate and primarily arises from social engineering.
OpenCVE Enrichment
Debian DLA
Debian DSA