Impact
The vulnerability is a missing authorization check in Chrome’s navigation handling, allowing a compromised renderer process to spoof the address bar through a specially crafted HTML page. This flaw does not grant arbitrary code execution or system compromise, but it can mislead users into believing they are on a different site, potentially facilitating phishing or social engineering attacks. The weakness is identified as a missing authorization control (CWE-862).
Affected Systems
Google Chrome versions prior to 154.0.8037.57 are affected. The vulnerability is fixed in Chrome 154.0.8037.57; the release date is not provided in the supplied information.
Risk and Exploitability
The CVSS score of 5.4 reflects a moderate impact. Exploitation requires the attacker to have already compromised the renderer process, so it is not a remote unauthenticated attack but rather a privilege escalation in the rendering context. Because EPSS is not available and the vulnerability is not listed in CISA KEV, the likelihood of active exploitation is currently low, though the potential to deceive users remains serious. Updating to the patched version eliminates the flaw. The attack vector is inferred to require local renderer compromise, and no specific additional exploit prerequisites are documented.
OpenCVE Enrichment
Debian DSA