Impact
In Google Chrome Enterprise, an insufficient validation of untrusted input (CWE-20) allows an attacker to craft an HTML page that mimics legitimate user interface elements, spoofing the UI to a user and potentially leading to deceptive interactions or unintended actions. While the flaw does not grant the attacker direct system control or denial of service capabilities, it undermines user trust and can facilitate social engineering attacks.
Affected Systems
Based on the description, the vulnerability is limited to the Enterprise edition of Google Chrome. All installations of Chrome Enterprise that have not yet applied the 150.0.7871.47 update are potentially vulnerable, regardless of the operating system on which the browser runs.
Risk and Exploitability
The CVSS score of 4.3 categorizes the issue as medium severity. The EPSS score of less than 1% indicates a very low but non-zero likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Remote delivery of a malicious HTML page and user interaction to render the spoofed interface drive the overall risk, which remains moderate and largely constrained by the low probability of successful exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA