Impact
This vulnerability allows an attacker who has convinced a user to install a malicious Chrome extension to inject arbitrary scripts or HTML into the browser through the Accessibility interface. The flaw, identified as a code injection weakness (CWE‑94), permits the injected content to be placed into the browser’s user interface.
Affected Systems
All users of Google Chrome versions before 149.0.7827.53 are impacted. The issue appears in the desktop Chrome stable channel and affects the Accessibility feature exposed to extensions. Any installation of a malicious or compromised extension that exploits this path is sufficient to trigger the flaw.
Risk and Exploitability
The exploit requires a malicious or untrusted extension to be installed; it is not a network‑remote attack vector. The EPSS score of <1% indicates a very low exploitation probability, and it is not listed in the CISA KEV catalog. The CVSS score of 5.4, indicating a Medium severity, suggests that once the malicious extension is installed, the injected scripts or HTML could be executed within the user’s browser context.
OpenCVE Enrichment
Debian DSA