Impact
The vulnerability lies in the Geometry implementation of Google Chrome before version 150.0.7871.47. An attacker can craft a malicious HTML page that, when a user performs specific UI gestures, displays spoofed interface elements. This deception may cause the user to interact with misleading content or submit sensitive information, exploiting a comparison‑deception weakness (CWE‑451).
Affected Systems
All installations of Google Chrome older than 150.0.7871.47 are affected. No other browsers or vendor products have been identified as impacted by this flaw.
Risk and Exploitability
The CVSS score of 4.2 indicates medium severity, while the EPSS score below 1 % shows a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is by an attacker that the user must visit and interact with; user gesture requirements reduce exploit likelihood.
OpenCVE Enrichment
Debian DLA
Debian DSA