Impact
An inappropriate implementation in the Downloads component of Google Chrome on macOS allows an attacker to convince a user to install a malicious extension, which can then perform UI spoofing. The flaw enables the attacker to manipulate the user interface to mislead the user into unintended actions. This vulnerability is typified by weaknesses such as deceptive UI components (CWE‑451).
Affected Systems
Google Chrome running on macOS versions prior to 148.0.7778.168 is affected. The vulnerability exists in the Downloads feature and can be exploited through any Chrome extension installed on these versions.
Risk and Exploitability
The CVSS score of 4.7 indicates a medium severity vulnerability, and no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog, suggesting it has not been observed in active exploitation. Exploitation requires social engineering to persuade the user to install a malicious extension, so the attack requires user interaction and is not remotely automated. The overall risk is moderate given the need for user action but still potentially significant because of the deceptive UI component.
OpenCVE Enrichment
Debian DSA