Impact
This vulnerability involves incorrect reference resolution in the Accessibility module of Google Chrome on macOS, allowing a remote attacker to craft a malicious HTML page that can spoof UI elements. The flaw could mislead users into interacting with deceptive controls or content, potentially facilitating phishing or social‑engineering attacks. Chromium assigns a medium severity to the issue.
Affected Systems
The issue affects Google Chrome browsers running on macOS systems prior to version 153.0.8010.36. Any Chrome installation on those builds that processes HTML content from an unknown source is potentially vulnerable.
Risk and Exploitability
Based on the description that a crafted HTML page can trigger the flaw, it is inferred that the attack vector is remote and does not require local privilege escalation. The EPSS score indicates a very low likelihood of exploitation, with a probability of less than 1 percent. The CVSS score of 4.3 reflects a medium severity flaw, and the vulnerability is not listed in the CISA KEV catalog. Despite the medium severity rating, the vulnerability can be abused in phishing campaigns or malicious websites aimed at users of vulnerable Chrome versions, especially if accessibility features are enabled.
OpenCVE Enrichment
Debian DLA
Debian DSA