Impact
The vulnerability is a missing authorization in Google Chrome that allows a remote attacker who has compromised the renderer process to spoof UI elements via a crafted HTML page. This flaw can be leveraged to create deceptive interfaces that may mislead users into taking unintended actions, though the exact consequences are not detailed in the advisory.
Affected Systems
All Google version older than 153.0.8010.47 are affected by this flaw.
Risk and Exploitability
The CVSS score of 4.2 indicates medium severity, and the EPSS score of less than 1% reflects a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that an attacker would need to first compromise the renderer process—likely via a malicious web page or compromised local code—and then deliver crafted HTML to trick the user. This creates a narrow attack surface primarily suited for targeted attacks rather than mass exploitation.
OpenCVE Enrichment