Impact
An improper access control flaw in Google Chrome’s media component on Windows allows a remote attacker who has already compromised the renderer process to spoof the browser’s UI through a crafted HTML page. The attacker can make the browser display forged interface elements that mislead users about the source of displayed information, effectively undermining the authenticity of the UI. This flaw is categorized as CWE-284.
Affected Systems
All Windows installations of Google Chrome older than version 150.0.7871.47 are affected. Specifically, any system running Chrome 150.0.7871.46 or earlier, where the media handling component has not been patched, is vulnerable to this exploitation technique.
Risk and Exploitability
The CVSS score of 6.5 classifies the vulnerability as medium severity. An EPSS score of less than 1% indicates a low probability of exploitation in the wild. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to have already gained control of the renderer process, meaning the vulnerability can only be leveraged after a prior foothold has been established. Under those conditions, the attacker can reliably spoof UI elements, but the overall risk remains moderate given the exploitation prerequisites.
OpenCVE Enrichment
Debian DLA
Debian DSA