Impact
The vulnerability is a missing authorization (CWE-862, CWE-1021) in Google Chrome that allows a remote attacker who has compromised the renderer process to spoof UI elements via a crafted HTML page. This flaw can be leveraged to create deceptive interfaces that may mislead users. The impact is limited to user interface spoofing, and no data exfiltration or privilege escalation is indicated in the advisory.
Affected Systems
Google Chrome versions older than 153.0.8010.47 are affected by this flaw.
Risk and Exploitability
The CVSS score of 4.2 indicates medium severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to first compromise the renderer process—likely via a malicious web page or compromised local code—and then deliver crafted HTML to trick the user. This creates a narrow attack surface primarily suited for targeted attacks rather than mass exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA