Impact
A flaw in the handling of CSS in Google Chrome versions before 150.0.7871.47 allows a remote attacker to craft an HTML page that causes arbitrary scripts or HTML to be executed in a victim’s browser. The vulnerability is an instance of Cross‑Site Scripting (CWE‑79).
Affected Systems
Google Chrome is the affected product. All0.7871.47 can be impacted; the vulnerability is fixed in version 150.0.7871.47 and later.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. The EPSS value of less than 1 % reflects a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Exploitation is likely remote, requiring a victim to open a crafted HTML page that triggers the as through a malicious link or embedded content.
OpenCVE Enrichment
Debian DLA
Debian DSA