Impact
This vulnerability is classified as CWE‑451, indicating an information exposure flaw. It occurs in the WebAppInstalls component of Google Chrome prior to version 153.0.8010.52, where a remote attacker can render UI elements that do not represent the actual page content. By delivering a specially crafted HTML page, the attacker can spoof interface elements—such as buttons or prompts—deceiving users into interacting with deceptive components. The impact is limited to user interface manipulation; the flaw does not provide direct code execution, data exfiltration, or system compromise. Instead, the main risk is social engineering fraud, phishing, or click‑jacking scenarios.
Affected Systems
Google Chrome browsers on all platforms that are running a version earlier than 153.0.8010.52 are affected. Updated releases beyond this version incorporate the fix and are not impacted.
Risk and Exploitability
The CVSS score of 5.4 is in the medium range, yet Chromium categorizes the flaw as low severity. Its EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to deliver a crafted web page that a victim visits and then socially engineer the user into interacting with the spoofed UI elements. No privileged or remote code execution capabilities are needed for exploitation, but a determined attacker could still misuse the deception for credential theft or other social engineering attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA