Impact
The flaw, categorized as CWE-20 (Improper Input Validation), allows a remote attacker with control over the renderer process to send crafted network traffic that can spoof user interface elements. The attack does not directly compromise data confidentiality or system integrity, but it can mislead users into interacting with falsified controls or content, creating a phishing or misinformation vector. The flaw is classified with Chromium security severity Low.
Affected Systems
Google Chrome browsers running versions earlier than 153.0.8010.36 are affected; all other recently updated versions are not susceptible.
Risk and Exploitability
Exploitation requires the attacker to already have compromised the renderer process, which limits the attack surface. The flaw cannot directly compromise data confidentiality or system integrity, so the primary impact is user interaction deception, potentially enabling phishing or misinformation. Chromium classifies this issue with a Low security severity; the CVSS score is 4.8. The EPSS score is < 1%, and the vulnerability is not listed in CISA’s KEV catalog. Users of older Chrome releases should update promptly to eliminate the UI spoofing risk.
OpenCVE Enrichment
Debian DLA
Debian DSA