Impact
The vulnerability allows a remote attacker to trick users into interacting with forged user interface components. By hosting a specially crafted HTML page, an attacker can present UI elements that appear to belong to Google Chrome, such as login prompts or permission dialogs. This spoofing can deceive users into revealing sensitive information, providing credentials, or granting permissions that they would not normally provide. The flaw is identified as CWE‑451, indicating that it results in unauthorized disclosure or misrepresentation.
Affected Systems
Google Chrome browsers on any platform updating before the release of version 153.0.8010.36 are affected. This includes desktop installations that have not yet applied the latest stable channel fix referenced in the Chrome release notes.
Risk and Exploitability
The CVSS score of 4.2 classifies the vulnerability as medium. The EPSS score is under 1%, and the vulnerability is not listed in CISA’s KEV database, indicating limited attack vector data at this time. The most likely exploitation path relies on a social engineering vector, where an attacker lures a user to a malicious web page or link. Once the user visits the page, the spoofed UI can be silently displayed, allowing the attacker to harvest credentials or other sensitive data. Because the vulnerability exploits only a visual trick and does not require code execution or elevated privileges, the scope of damage depends heavily on user susceptibility, but successful exploitation could result in credential theft or unauthorized data access.
OpenCVE Enrichment
Debian DLA
Debian DSA