Impact
A race condition exists in Chrome's WebAppInstalls component that permits an attacker to load a specially crafted HTML page. This race condition (CWE-362) can cause UI elements to be rendered or updated in a different order than intended, potentially mimicking legitimate controls. If an end user interacts with the spoofed UI, they may be tricked into exposing sensitive data or performing unintended actions.
Affected Systems
Google Chrome browsers running any version before 153.0.8010.47 on any platform are susceptible. The issue was addressed in the 47 update and subsequent releases.
Risk and Exploitability
The vulnerability carries a Medium severity rating. EPSS indicates less than a 1% exploitation likelihood. It is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is a malicious or compromised webpage that a vulnerable user visits. Exploitation requires no privileged access and only a user to open the crafted page, making it a convenient vector for phishing or social engineering campaigns.
OpenCVE Enrichment