Impact
A vulnerability in Google Chrome for Windows before version 153.0.8010.36 allows a remote attacker to misrepresent the user interface in full‑screen mode by serving a crafted HTML page (CWE-451). The browser may render UI elements that appear to be legitimate controls or dialogs, while actually being supplied by the attacker. This misrepresentation can create user interactions that are deceptive and may lead to actions performed without the user’s informed consent.
Affected Systems
Google Chrome on desktop Windows systems running any stable channel release earlier than 153.0.8010.36 is affected. All versions of the browser on Windows that have not yet been updated to this or later revision inherit the flaw.
Risk and Exploitability
The flaw is classified as a medium severity vulnerability with a CVSS score of 5.4. The EPSS score indicates a very low exploitation probability (< 1%) and it is not listed in CISA’s KEV catalog. The attack vector requires a remote web page that requests full‑screen mode and the attacker must persuade the user to grant the request. Because the exploitation relies on user interaction, the overall risk is modest but should not be overlooked in environments where users frequently visit untrusted sites.
OpenCVE Enrichment
Debian DLA
Debian DSA