Impact
A flaw in Google Chrome’s session handling allows a remote attacker to send a specially crafted HTML page that is rendered by Chrome’s own UI components, causing the browser to display deceptive interface elements such as dialog boxes, password prompts, or buttons that do not correspond to the real origin of the content. This vulnerability is classified as CWE‑451 and results in UI misrepresentation without providing a path to arbitrary code execution or the disclosure of sensitive data.
Affected Systems
All installations of Google Chrome older than version 153.0.8010.36, across Windows, macOS, Linux, and Chrome OS, are potentially affected. The issue applies to stable channel releases as well as any custom builds that have not yet incorporated the update. Users of older stable channel versions or custom builds that did not install the patch remain vulnerable until they upgrade.
Risk and Exploitability
Exploitation requires the attacker to deliver a maliciously crafted page which the victim must visit, after which Chrome will render the deceptive UI elements. The CVSS score of 5.4 confirms a medium severity rating, and the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation in the wild. EPSS is less than 1%, reflecting a very low probability of abuse. The risk remains largely limited to phishing or social‑engineering opportunities rather than direct compromise or data theft. The attack vector is inferred to rely on user interaction with a compromised site, so the probability of exploitation remains moderate under the current circumstances.
OpenCVE Enrichment
Debian DLA
Debian DSA