Impact
A flaw in Google Chrome on Linux allows an extension, once installed, to spoof the browser’s user interface, creating counterfeit dialog boxes or interface elements that can deceive users into revealing credentials or performing unintended actions. The vulnerability stems from insufficient policy enforcement for extensions and is classified as CWE-451. The CVSS score is 3.1.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 on Linux operating systems are affected. The issue is tied to how extensions are managed before this patch release, impacting any Chrome session extension is active.
Risk and Exploitability
The vulnerability is not listed in CISA’s KEV catalog, and the EPSS score is < 1%, indicating limited publicly known exploitation. The CVSS score of 3.1 reflects low severity. The likely attack vector requires a user to be persuaded to install a malicious extension; once installed, the extension runs with browser privileges and can manipulate UI elements, leveraging the spoofing capability for phishing or deceptive interactions. The Medium Chromium severity suggests a moderate risk to users that install untrusted extensions.
OpenCVE Enrichment
Debian DLA
Debian DSA