Impact
The flaw in Chrome causes the browser to display an incorrect banner or visual cue when a website enters fullscreen mode, making users believe the page is secure or privileged. This deception can be leveraged for phishing or other social‑engineering attacks. The likely attack vector, inferred from the description, involves a remotely controlled web page that requests fullscreen and then presents a spoofed UI.
Affected Systems
Google Chrome versions earlier than 148.0.7778.168 are affected. The issue is triggered only when a webpage initiates fullscreen; no specific operating system or channel is mentioned.
Risk and Exploitability
The CVSS score of 5.4 indicates medium severity. The EPSS score is reported as less than 1 %, suggesting a low chance of exploitation. The vulnerability is not listed in the CISA KEV catalog. Because the exploit requires a malicious webpage that can request fullscreen, it is remotely exploitable but limited to users who visit a compromised site. The attack vector is inferred rather than explicitly stated in the CVE data.
OpenCVE Enrichment
Debian DSA