Impact
This vulnerability results from insufficient validation of untrusted input in the WebAppInstalls component of Google Chrome on Windows, classified as CWE-20. A remote attacker can supply a crafted HTML page that, when the user performs specific UI gestures, causes arbitrary code to execute within the browser, potentially taking control of the affected system.
Affected Systems
Google Chrome for Windows versions earlier than 150.0.7871.47 are affected. Any user running these releases may be vulnerable if they view a maliciously constructed page and perform the required gestures.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in CISA KEV. Exploitation requires user interaction with a malicious webpage.
OpenCVE Enrichment
Debian DLA
Debian DSA