Impact
The vulnerability stems from an improper implementation of the Media component in Google Chrome on Windows, which permits a remote attacker who has already taken control of the renderer process to load a specially crafted HTML page that causes the browser’s user interface to be spoofed. This flaw is an instance of CWE-284, an access control weakness that allows UI manipulation and could mislead users about the source or authenticity of the displayed content.
Affected Systems
Google Chrome browsers running on Windows with versions older than 150.0.7871.47 are affected. Systems that have not applied the 150.0.7871.47 or newer patch are vulnerable to this UI spoofing flaw.
Risk and Exploitability
The CVSS score of 6.5 characterizes the vulnerability as medium severity, while an EPSS score of less than 1 % indicates a low likelihood of widespread exploitation in the general population. The flaw is not listed in the CISA KEV catalog. Exploitation requires an attacker to first compromise the renderer process, after which an attacker can deliver a crafted HTML page to alter the UI. Because the technique depends on a prior renderer compromise, the overall risk remains moderate, but any system that is susceptible to renderer exploitation should treat this flaw as a potential vector for UI manipulation.
OpenCVE Enrichment
Debian DLA
Debian DSA