Impact
Google Chrome’s payment user interface can be misrepresented by a remote attacker through a crafted HTML page. The flaw, classified as CWE‑451 and CWE‑1021, allows an attacker to replace genuine payment prompts with counterfeit elements that look legitimate, potentially causing users to unknowingly submit payment information or confirm transactions. The vulnerability does not provide a pathway to execute code or gain elevated privileges; it simply deceives the user through visual manipulation, and the Chromium team rates it as Medium severity.
Affected Systems
All desktop installations of Google Chrome that are running versions earlier than 153.0.8010.36 are affected. Versions 153.0.8010.36 and later contain the fix that blocks the UI misrepresentation attack.
Risk and Exploitability
The most likely attack vector is a malicious webpage that a user visits, which uses the payment UI to display spoofed dialogs. Because the flaw resides in the rendering pipeline for payment pages, it does not require additional user input beyond normal browsing. The CVSS score of 5.4 indicates a medium severity risk, and the EPSS data is not available. The vulnerability is not listed in the CISA KEV catalog, suggesting no documented large‑scale exploitation yet. The Medium severity rating indicates a moderate risk of financial fraud if a user falls for the deception. No elevated privileges or system compromise are required.
OpenCVE Enrichment
Debian DLA
Debian DSA