Impact
A flaw in the Geometry component of Google Chrome before version 153.0.8010.36 allows a remote attacker to craft an HTML page that misrepresents UI elements, effectively spoofing user interface components. This misrepresentation can lead to deceptive interactions, such as tricking users into trusting false prompts or buttons, and is classified as a medium severity vulnerability by Chromium security. The weakness involves improper handling of rendering metadata, as indicated by its CWE-451 classification.
Affected Systems
All installations of Google Chrome that are using a Geometry component prior to the 153.0.8010.36 release are affected. This includes stable channel builds older than the update referenced in the Chrome release blog. The vulnerability applies to any user who can load a malicious page in their browser, regardless of operating system. The affected product is Google Chrome; the vulnerable version range ends at 153.0.8010.35 and earlier.
Risk and Exploitability
The vulnerability is exploitable via a crafted web page, requiring the victim to visit the malicious site. Because the EPSS score is 0.00208 (~0.21%) and the flaw is not listed in CISA’s KEV catalog, known exploitation activity is not documented, but the attack vector is clear and the potential for social engineering is high. The medium severity index, with a CVSS score of 5.4, reflects the risk of user deception and the likelihood of the attacker’s success given the ease of page loading and the lack of defensive mitigations in the affected release.
OpenCVE Enrichment
Debian DLA
Debian DSA