Impact
The vulnerability allows a remote attacker to craft an HTML page that causes Chrome to display misleading UI elements. This UI misrepresentation can deceive users into interacting with forged dialogs or prompts. Based on the description, it is inferred that users may mistakenly submit credentials or perform unintended actions on a spoofed interface. The vulnerability is categorized as CWE-451.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected.
Risk and Exploitability
The flaw is scored 5.4 on the CVSS scale, indicating moderate severity. The EPSS score is less than 1 %, suggesting a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote via delivery of a crafted HTML page over HTTP or HTTPS, which the browser will render without additional user interaction. Because it requires no special privileges, the exploit can be triggered by any user who visits a malicious page.
OpenCVE Enrichment
Debian DLA
Debian DSA