Impact
The vulnerability is a UI misrepresentation in the Downloads interface of Google Chrome. A crafted HTML page can cause a user to misinterpret the status of a download, leading them to allow the download under the false impression that it is safe. This misrepresentation allows a remote attacker to exploit social engineering tactics to bypass system access restrictions. The weakness corresponds to CWE-451, representing best‑practice violations that present a technical security weakness.
Affected Systems
Google Chrome browsers prior to version 153.0.8010.36 are affected. Users employing these older Chrome releases are at risk if they visit malicious or misleading web pages that exploit the UI flaw.
Risk and Exploitability
The EPSS score is less than 1%, indicating a very low probability of exploitation. The CVSS score is 5.4, which classifies the vulnerability as Medium severity. The vulnerability is not listed in the CISA KEV catalog. The defined severity for Chromium is Medium, indicating a reasonable but not imminent risk if users are targeted. The likely attack vector is remote, from a crafted HTML page accessed over the web. Exploitation requires the user to interact with the malicious page, meaning the vector relies on social engineering rather than a pure technical exploit. The absence of an active exploit in the wild reduces immediate risk, yet the possibility of targeted attacks exists.
OpenCVE Enrichment
Debian DLA
Debian DSA