Impact
The vulnerability is an incorrect authorization check in Chrome's isolated origins handling that lets a remote attacker craft an HTML page to spoof user interface elements. The attacker can make legitimate UI controls appear in a fake context, potentially leading to credential theft or deceptive input collection. This flaw does not allow code execution but grants persuasive fraud capabilities against users. The weakness is identified as CWE‑863. The likely attack vector is a crafted web page opened by the victim in Chrome, as confirmed by the Chromium release notes.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are affected. No other vendors or products are listed in the CNA data. The flaw applies to any Chrome installation running the affected builds; product details such as specific platforms or builds are not provided, so any installation of Chrome running an affected version could be vulnerable.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity. The EPSS score is < 1%, indicating a very low publicly available exploitation probability. The vulnerability is not listed in CISA's KEV catalog. Attack exploitation requires the victim to open a maliciously crafted page in Chrome; no privileged or local conditions are needed. Therefore the risk is moderate due to the potential for phishing and credential compromise, but it does not provide remote code execution or broader system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA