Impact
The flaw originates from insufficient validation of untrusted HTML content in Chrome's Guest View feature, pre‑version 149.0.7827.103. A remote attacker can craft an HTML page that, when opened in Chrome, triggers UI elements that appear legitimate to the user. This can lead to misleading user interactions. The weakness involves improper input validation (CWE‑20) and improper preparation of source data (CWE‑1021).
Affected Systems
All Google Chrome installations older than 149.0.7827.103 across Linux, macOS and Windows are affected.
Risk and Exploitability
The reported CVSS score of 5.4 indicates medium severity, while an EPSS score of <1% implies a very low but non‑zero likelihood of exploitation. The vulnerability is not included in the CISA KEV catalog. Exploitation requires the attacker to host a malicious webpage that is rendered within Guest View and the target user to open that page in Chrome.
OpenCVE Enrichment
Debian DSA