Impact
Insufficient policy enforcement for the WebView tag in Google Chrome versions before 143.0.7499.192 allows a malicious Chrome Extension to inject scripts or HTML into privileged web pages. The injected code runs with the privileges of the page, giving an attacker the ability to execute arbitrary code in a privileged context and potentially compromise the confidentiality, integrity, and availability of the user's data and the host system. The weakness is classified as CWE-862: Authorization Bypass via Privilege Escalation.
Affected Systems
All installs of Google Chrome with a version older than 143.0.7499.192 are impacted, regardless of operating system. The vulnerability manifests when a user accepts or installs a Chrome Extension that exploits the WebView tag to target privileged pages.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity, and the EPSS score of 7% suggests a moderate likelihood of exploitation. Although the vulnerability is not listed in the CISA KEV catalog, attackers can leverage the flaw by convincing a user to install a malicious extension; once installed, their scripts can be injected into privileged pages without additional network-level intrusion. Risk is therefore highest for environments that permit extension installation and process sensitive web content.
OpenCVE Enrichment
Debian DSA