Impact
The vulnerability allows a remote attacker who has already compromised the browser renderer process to present fabricated UI elements on the Passwords page in Chrome for Android. This misrepresentation can trick a user into believing legitimate requests are genuine, enabling credential theft through social engineering without actually executing code outside the browser sandbox. The described weakness relies on improper visual validation of sensitive UI elements and thus exposes users to phishing attacks.
Affected Systems
Google Chrome for Android versions earlier than 153.0.8010.36 are affected. Any device running a pre‑153.0.8010.36 release can be vulnerable if an attacker can render a malicious page while running the renderer process.
Risk and Exploitability
The CVSS base score of 4.2 (Low) reflects that this is a low‑severity issue, and the EPSS score of <1% suggests that widespread exploitation is unlikely. The vulnerability requires that the attacker has already compromised the browser’s renderer process to deliver a crafted page, limiting the attack surface to sophisticated threat actors. Because the prerequisite of renderer compromise exists, the overall risk remains modest, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, credential theft remains possible if an attacker can inject malicious content into a Chrome browser session.
OpenCVE Enrichment
Debian DLA
Debian DSA