Impact
An unsafe implementation in Google Chrome’s CSS engine permits a remote attacker to inject arbitrary scripts or HTML by serving a specially crafted page. The injected code runs within the page’s context and can perform any JavaScript activity available to a loaded page, enabling classic cross‑site scripting. This could allow an attacker to read or modify page data, steal credentials, or redirect users. The vulnerability is limited to the rendering of crafted HTML and does not require elevated privileges.
Affected Systems
Google Chrome users on any release before 149.0.7827.53 are affected. The issue is present in the stable channel releases prior to 149.0.7827.53 and is fixed in that version and later.
Risk and Exploitability
Chromium lists the severity as Medium, with a CVSS score of 6.1 and an EPSS score of < 1%. The vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploitation reports at this time. The attack vector is remote; an attacker must deliver or host a malicious HTML page that the victim opens. Exploitation does not require system privileges but can execute arbitrary JavaScript in the context of the page, potentially compromising user data or enabling phishing.
OpenCVE Enrichment
Debian DSA