Impact
Google Chrome versions before 149.0.7827.53 contain insufficient validation of untrusted input in the omnibox, allowing a remote attacker who convinces a user to perform specific UI gestures to inject arbitrary scripts or HTML (UXSS). This flaw is classified as CWE‑20 (Improper Input Validation) and CWE‑79 (Cross‑Site Scripting), enabling execution of injected scripts in the browser context, potentially compromising user data, credentials, or other browser state.
Affected Systems
All desktop releases of Google Chrome on all operating systems for which the build number is less than 149.0.7827.53 are affected. Users running older stable releases without this update remain vulnerable.
Risk and Exploitability
The vulnerability is scored by Chromium with a CVSS vector of 6.1; EPSS is <1%, indicating a low but nonzero threat that an adversary could exploit. The attack requires a victim to first open a crafted HTML page and then perform specific UI gestures; therefore, successful exploitation relies on user interaction. The exploitability is limited by the requirement for user action and the need for the browser version to be older than 149.0.7827.53. The flaw is not listed in CISA’s KEV catalog.
OpenCVE Enrichment
Debian DSA