Impact
Google Chrome versions prior to 153.0.8010.36 contain a UI misrepresentation flaw in the UrlFormatting component. A remote attacker can craft a domain name that appears legitimate in the address bar, enabling a phishing attack that deceives users into believing they are visiting a trusted site. The weakness is classified as CWE‑451, exposing sensitive browsing context information to the user.
Affected Systems
All installations of Google Chrome with a version older than 153.0.8010.36 are affected, regardless of operating system. The flaw exists on all platforms where those versions are running.
Risk and Exploitability
Exploitation requires the victim to interact with a link or page controlled by the attacker; the attacker must convince the user to click on a crafted URL. This user‑interaction requirement is inferred from the description of the vulnerability. The CVSS score of 5.4 rates it as Medium severity, and the EPSS score of <1% suggests a low, but non‑zero, likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, it can still facilitate credential theft or phishing if users are deceived.
OpenCVE Enrichment
Debian DLA
Debian DSA