Impact
The vulnerability allows a remote attacker to create a malicious web page that mimics password entry dialogs within Google Chrome, leading to UI spoofing. This can trick users into entering credentials into a fake prompt, compromising confidentiality of authentication data. The weakness is identified as CWE‑451, indicating a failure of the user interface to accurately reflect the true state of the application.
Affected Systems
Google Chrome users prior to version 153.0.8010.36 are affected. The flaw resides in the password handling components of Chrome and was fixed in the 153.0.8010.36 release.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium‑severity flaw that can be exploited through a simple phishing web page hosted on any site. The EPSS score of 0.00174 indicates a very low exploitation probability, and the vulnerability is not listed in CISA’s KEV catalog. Attackers can exploit this without special prerequisites, but only when the victim visits a crafted page and interacts with the spoofed dialog. The severity and lack of mitigation tooling combine to make timely patching essential.
OpenCVE Enrichment
Debian DLA
Debian DSA