Impact
Improper input validation in Chrome interstitial pages permits remote attackers to craft HTML that displays spoofed UI components such as warning banners or dialog boxes. Because interstitials can be rendered by the browser with an elevated envelope, the attacker can cause the victim to see UI that appears legitimate but is actually controlled by the attacker. Based on the description, it is inferred that the attacker could influence user actions by manipulating the perceived authenticity of UI elements.
Affected Systems
Google Chrome browsers on all operating systems running a version earlier than 153.0.8010.36 are vulnerable. The defect was corrected in Chrome 153.0.8010.36 and later.
Risk and Exploitability
The CVSS score is 5.4, classified as Medium. The EPSS score is <1% indicating a very low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to serve a malicious HTML page to a victim; because the flaw is client‑side the attack vector is Remote (web‑based). The impact is limited to the targeted user’s browser session, though spoofed UI could mislead the user.
OpenCVE Enrichment
Debian DLA
Debian DSA