Impact
A remote attacker can craft a web page that, when viewed in Chrome, displays user interface elements inside the ExtensionsMenu that do not actually exist. This misrepresentation can make a user believe that a trusted extension or request is active when it is not, allowing the attacker to trick the user into taking unintended actions, such as approving a malicious extension or clicking a deceptive link. The flaw is a user interface spoofing vulnerability identified as CWE‑451.
Affected Systems
All users running Google Chrome versions earlier than 154.0.8037.57 on any platform are affected. The flaw lies in the ExtensionsMenu rendering logic and impacts any Chrome browser that implements this menu interface.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate risk; an attacker does not need to exploit a code execution vector, only a crafted HTML page delivered remotely. The EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog. The likely attack path is social engineering: an attacker hosts a malicious webpage that displays spoofed menu items when a user visits the site, leading them to perform unintended actions.
OpenCVE Enrichment
Debian DSA