Impact
This vulnerability is caused by improper input validation in FedCM, the Federated Credential Management API, in Google Chrome versions prior to 153.0.8010.36. When an attacker gains control of the renderer process, they can deliver a crafted HTML page that causes the browser to display spoofed UI elements. The result is a UI spoofing attack that enables phishing or other social‑engineering exploits, potentially misleading users into submitting sensitive information or interacting with malicious content. The weakness is an insecure input validation flaw (CWE-20).
Affected Systems
All users running Google Chrome on the stable channel before version 153.0.8010.36 are impacted. The vulnerability was discovered in the Chrome renderer component used across all supported operating systems.
Risk and Exploitability
The risk level is Medium according to the Chromium security severity assessment and the CVSS base score is 4.2, confirming a medium severity. Exploitation requires the attacker to have already compromised the renderer process. It is inferred that common causes of such renderer compromise include memory corruption or code‑execution flaws, though this is not explicitly stated in the CVE. The EPSS score is < 1%, and the vulnerability is not listed in the CISA KEV catalog. Given the need for a renderer compromise, the likelihood of successful exploitation is limited but not negligible in environments where other renderer vulnerabilities exist. The attacker can only spoof UI elements; there is no direct remote code execution or data exfiltration capability disclosed by the CVE statement. Nonetheless, the potential for phishing and user deception warrants prompt remediation.
OpenCVE Enrichment
Debian DLA
Debian DSA