Impact
A remote attacker can craft an HTML page that takes advantage of a misrepresentation bug in the FedCM authentication UI in Google Chrome. The bug allows social engineering attacks by spoofing various UI elements normally displayed during a FedCM session. As a result, a user might be misled into believing a legitimate authentication prompt is part of the browser, potentially enabling credential theft or other malicious actions. The initial reporter noted the issue as Medium severity in the Chromium security releases.
Affected Systems
All installations of Google Chrome that are operating on a release earlier than 153.0.8010.36 are vulnerable. The affected versions span all supported operating systems, as the flaw is in the cross‑platform FedCM implementation.
Risk and Exploitability
The vulnerability is publicly known, and the EPSS score is < 1%, and the asset is not listed in the CISA KEV catalog. The attack requires a user to open a crafted webpage and visually interact with the spoofed UI; thus exploitation is feasible in social engineering contexts. The CVSS score of 5.4 indicates a medium severity, and the lack of advanced exploitation prerequisites suggest a moderate risk that warrants timely remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA