Impact
This vulnerability is caused by insufficient policy enforcement in Google Chrome extensions prior to 149.0.7827.53, allowing a malicious extension to inject scripts or HTML into a privileged page. The injected content runs with Chrome's highest privileges, combining the risk of privilege escalation (CWE‑602) and cross‑site scripting (CWE‑79) as the content can execute arbitrary JavaScript in a privileged context. Based on the description that the payload executes as a privileged extension, it is inferred that the attacker could tamper with the browser environment, compromise the user session, or exfiltrate data.
Affected Systems
All users running Google Chrome versions older than 149.0.7827.53 are affected, regardless of operating system, as the flaw is present in the core extension handling code.
Risk and Exploitability
The vulnerability has a CVSS score of 4.3, indicating a moderate impact. The EPSS score of < 1% suggests a low likelihood of exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Based on the description, the likely attack vector requires convincing a user to install a malicious extension—typically via phishing, social engineering, or bundled software. Once installed, the extension can inject and execute code in privileged contexts, giving the attacker high‑level control over the user’s Chrome session and potentially beyond. Due to the lack of widespread exploitation evidence, the immediate likelihood is moderate, yet the capability warrants timely action.
OpenCVE Enrichment
Debian DSA