Impact
Clickjacking of the Downloads UI allows a remote attacker to craft a web page that mimics native download prompts, tricking users into submitting unintended actions. The flaw enables the attacker to spoof confirmation dialogs and other UI elements, potentially leading to accidental downloads of malicious content or unintended user interactions. The weakness is classified as CWE-1021.
Affected Systems
Google Chrome browsers running any version earlier than 153.0.8010.36 are affected. The vulnerability appears in the Downloads component and does not require local exploitation or elevated privileges.
Risk and Exploitability
The CVSS score of 5.4 indicates a Medium severity. The EPSS score is less than 1% and the vulnerability is not listed in the CISA KEV catalog, indicating no known large‑scale exploitation. Nonetheless, if an attacker successfully deceives a user with a crafted page, they can force the user to initiate a download or trigger a UI element. The attack requires social engineering but no additional network or privilege exploitation steps beyond delivering a malicious HTML page.
OpenCVE Enrichment
Debian DLA
Debian DSA