Impact
An incorrect authorization check in the Downloads feature of Google Chrome before version 153.0.8010.36 allows a remote attacker who has already compromised the renderer process to deliver a crafted HTML page that can spoof user interface elements. This flaw permits the attacker to display counterfeit UI components, potentially misleading users about download actions or other interactions. The vulnerability is a classic instance of improper authorization (CWE‑863).
Affected Systems
Google Chrome users running any version prior to 153.0.8010.36 are affected. The issue is limited to the Downloads functionality and requires the attacker to have control over the renderer process to deliver the malicious page.
Risk and Exploitability
The CVSS score of 4.2 indicates a medium severity. The EPSS score is < 1%, indicating a very low probability of exploitation, and the flaw is not listed in the CISA KEV catalog. Exploitation requires prior compromise of the renderer process; once achieved, the attacker can craft content that triggers UI spoofing. The risk is moderate because the threat does not allow remote code execution, but the impact on user trust and potential for phishing remains significant.
OpenCVE Enrichment
Debian DLA
Debian DSA