Impact
This vulnerability is a race condition in Chrome’s Payments component that allows a remote attacker to craft an HTML page that spoofs payment‑UI elements. By exploiting improper synchronization in the handling of payment‑UI events, the attacker can replace or manipulate these elements before they are rendered, creating a forged interface that appears legitimate. The attacker relies on user interaction and social engineering and can cause users to approve unauthorized transactions or reveal credentials through the deceived UI.
Affected Systems
The flaw affects all Google Chrome releases before version 153.0.8010.36 on every supported operating system. Users running an older build are vulnerable if they visit a malicious website that hosts the crafted payment interface.
Risk and Exploitability
The CVSS score is 5.4, which falls into the medium severity range, indicating that exploitation requires user interaction. The EPSS score is < 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is remote via a malicious webpage, and the risk is realistic in environments where users frequently interact with payment prompts and may not recognize phishing attempts.
OpenCVE Enrichment
Debian DLA
Debian DSA