Impact
The flaw permits a remote attacker to craft a malicious HTML page that causes Chrome’s Downloads page to display UI elements that look like genuine system dialogs. This UI misrepresentation can deceive a user into believing that a file download is legitimate, which is inferred to potentially lead to the download of malware or disclosure of sensitive information. The weakness is identified as CWE‑451. The vulnerability permits social engineering through spoofed UI elements, posing a moderate risk of phishing or unauthorized file downloads.
Affected Systems
Google Chrome versions prior to 153.0.8010.36 are affected. Users installed with these earlier releases of Chrome are vulnerable to the UI spoofing issue. All platforms running Chrome on non‑stable channels before the specified update are included.
Risk and Exploitability
The attack vector is remote; an attacker can host the crafted page on the web and lure a user to invoke Chrome’s Downloads dialog. Chromium labels the severity of this issue as Medium and the CVSS score is 5.4. The EPSS score is less than 1%, indicating a low likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Consequently the likelihood of exploitation is uncertain, but the potential impact is significant for users who rely on the authenticity of download prompts, which is inferred.
OpenCVE Enrichment
Debian DLA
Debian DSA