Impact
A confused‑deputy flaw in Chrome’s Fullscreen feature lets an attacker who has already compromised the renderer process craft HTML that can spoof user interface elements. The vulnerability does not provide direct code execution; it allows the attacker to trick users into interacting with elements appearing legitimate. The weakness is categorized as CWE‑441 – Confused Deputy.
Affected Systems
Chromium, specifically Google Chrome versions prior to 153.0.8010.36, are affected. Updated builds of Chrome that ship with the full‑screen request handling fix are not impacted.
Risk and Exploitability
Based on the description, the likely attack vector is a malicious page that a user is tricked into loading, which would give the attacker control of the renderer process; this prerequisite is non‑trivial. The EPSS score of < 1% combined with the CVSS score of 4.2 indicates a low likelihood of widespread exploitation and a low severity impact. The flaw is not listed in the CISA KEV catalog, corroborating its limited exploitability. As described, the vulnerability permits successful phishing or credential‑stealing attempts through spoofed UI elements.
OpenCVE Enrichment
Debian DLA
Debian DSA