Impact
extension framework before version 150.0.7871.47. A malicious extension that has been installed by the user can, allowing an attacker to deceive users into interacting with misleading or deceptive UI. The weakness is identified as CWE-451. No exploitation of system resources or data beyond UI deception is described.
Affected Systems
The vulnerability affects users of Google Chrome on desktop operating systems running versions older than 150.0.7871.47. The CVE text does not explicitly name particular OS platforms; this absence of explicit mention is an inferred assumption that desktop platforms are impacted, while Android, Chrome OS, or other non‑desktop environments are not specifically listed and therefore are presumed not to be affected.
Risk and Exploitability
The CVSS score of 3.1 indicates low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to install a malicious extension, which typically depends on social engineering rather than network‑level or privileged‑access attacks. Consequently, the risk is primarily limited to attackers who can persuade users to add a suspicious extension.
OpenCVE Enrichment
Debian DLA
Debian DSA