Impact
A remote attacker can craft a malicious HTML page to cause Google Chrome on Android to display incorrectly rendered UI elements within its Messages interface, enabling the attacker to spoof legitimate UI components and potentially deceive users into providing sensitive information or unknowingly interacting with malicious content.
Affected Systems
The flaw affects Google Chrome on Android versions prior to 154.0.8037.57, specifically the Messages component that handles web content. Users running any Android device with Chrome older than that revision are at risk.
Risk and Exploitability
The CVSS base score of 5.4 indicates a medium severity. With no EPSS score available and the vulnerability not listed in CISA KEV, the current exploitation probability appears modest, but the lack of a publicly known exploit does not guarantee absence of risk. Attackers would need to lure a user to a malicious page through social engineering, making user education a relevant countermeasure. Once triggered, the attacker could present spoofed UI elements that mimic legitimate prompts.
OpenCVE Enrichment
Debian DSA