Impact
This vulnerability enables a remote attacker to deliver a malicious HTML page that forces Google Chrome on Android to display forged password prompts. The UI misrepresentation, identified as CWE‑451, lets the attacker trick users into entering credentials into a counterfeit dialog, compromising confidentiality of login information. The flaw is purely client‑side and depends on the browser rendering the crafted page.
Affected Systems
The affected product is Google Chrome for Android prior to version 153.0.8010.36. Devices running any older Chrome version are susceptible, while the 153.0.8010.36 stable channel update implements the necessary UI validation to prevent spoofing.
Risk and Exploitability
Chromium rates this issue with low severity (CVSS 5.4), and it is not listed in the CISA KEV catalogue. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. The flaw can be exploited remotely by tricking a user into visiting a malicious page, making it suitable for phishing attempts against Android Chrome users who have not yet updated.
OpenCVE Enrichment
Debian DLA
Debian DSA