Impact
Google Chrome Enterprise prior to version 150.0.7871.47 contains an insufficient validation of untrusted input that permits a remote attacker to create a crafted HTML page triggering UI spoofing. The flaw does not grant system control or cause denial of service but interferes with the authenticity of the browser’s interface, potentially misleading users.
Affected Systems
All installations of Google Chrome Enterprise that have not yet applied the 150.0.7871.47 update are vulnerable, regardless of operating system.
Risk and Exploitability
The CVSS score of 4.3 indicates medium severity. The EPSS score of less than 1% shows a very low but non‑zero likelihood of exploitation, and the vulnerability is not listed in CISA KEV. The likely attack vector is a remote attacker distributing a malicious HTML page that the victim opens in Chrome Enterprise; based on the description, the exploitation requires user interaction to load the crafted content.
OpenCVE Enrichment
Debian DLA
Debian DSA