Impact
Based on the description, it is inferred that the vulnerability is an improper handling of CSS parsing in Google Chrome versions released before 150.0.7871.47, which falls under CWE‑346. When a user loads a crafted HTML page that includes malicious CSS, the browser may incorrectly trust the CSS instructions, leading to a bypass of the same‑origin policy. This allows an attacker to read or modify data that belongs to a different web origin, potentially resulting in data theft or injection of malicious content across domain boundaries.
Affected Systems
All installations of Google Chrome that are running a version earlier than 150.0.7871.47 are affected. The CVE does not specify a particular release channel; therefore any channel that includes an unpatched version before the fix is at risk.
Risk and Exploitability
Based on the description, it is inferred that exploitation requires a maliciously constructed HTML page that the user visits, allowing the attacker to remotely bypass the policy. The CVSS score of 6.5 indicates moderate severity, while the EPSS score of less than 1% suggests a very low probability of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog, implying no known active exploit campaigns.
OpenCVE Enrichment
Debian DLA
Debian DSA