Impact
The vulnerability is a UI misrepresentation in the Geometry component of Google Chrome up through version 153.0.8010.35. A crafted HTML page can cause the browser to incorrectly render UI elements, allowing a remote attacker to spoof legitimate UI controls. This can lead users to interact with fake buttons or links, potentially facilitating phishing or credential theft. The flaw represents information exposure that undermines interface trust (CWE-451).
Affected Systems
Google Chrome browsers on all operating systems before the 153.0.8010.36 release are affected. The patch is included in Chrome version 153.0.8010.36 and later; any installation with a lower build number remains vulnerable.
Risk and Exploitability
Because the attacker relies on a social‑engineering attack vector—delivering a malicious HTML page—the compromise requires the victim to open or interact with the crafted content. The EPSS score is <1%, suggesting a low likelihood of exploitation, and the vulnerability is not listed in CISA's KEV catalog, indicating medium risk. The CVSS score of 5.4 confirms medium severity, matching Chromium's Medium classification. While no remote code execution exists, an attacker can stealthily alter the user interface to prompt unintended user actions.
OpenCVE Enrichment
Debian DLA
Debian DSA