Impact
This vulnerability is a clickjacking flaw in Google Chrome that is only exploitable after an attacker has already compromised the browser’s renderer process. By exploiting the flaw, a malicious page can overlay or hide legitimate UI controls and trick a user into interacting with elements that appear to be part of the normal interface. The impact is confined to the user’s interaction with the browser – the attacker cannot execute arbitrary code or gain broader system access through this flaw alone, but can cause unintended actions or facilitate additional phishing attempts.
Affected Systems
Google Chrome, all versions preceding 153.0.8010.36. No specific minor release numbers are mentioned beyond the affected threshold. Users running Chrome 152.x or earlier are vulnerable.
Risk and Exploitability
The vulnerability requires a pre‑existing compromise of the renderer process, which is a significant prerequisite. The exploit also relies on successful social engineering to persuade a user to visit a crafted page. Because the CVSS score of 4.2 is low and the EPSS score is less than 1%, the current threat level is modest. The flaw is not listed in CISA’s KEV catalog, reinforcing its limited immediate exploitability. However, if a renderer compromise mechanism is discovered in the future, this clickjacking route could become more actionable.
OpenCVE Enrichment
Debian DLA
Debian DSA