Impact
The vulnerability stems from incorrect handling of the Extensions UI in Google Chrome versions prior to 150.0.7871.47. An attacker who succeeds in convincing a user to install a malicious extension can activate the flaw by navigating to a specially crafted web page, which allows injection of arbitrary scripts or HTML. This is a user‑experience cross‑site scripting (UXSS) vulnerability that permits code execution within the browser context.
Affected Systems
Any installation of Google Chrome that is older than version 150.0.7871.47 is susceptible. This includes all desktop releases of Chrome (Windows, macOS, Linux) before the patch was released.
Risk and Exploitability
The CVSS score is 4.2 (Medium). The EPSS score is <1%, indicating a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to persuade the user to install an untrusted extension and then visit a crafted web page; the effect is execution of arbitrary script or HTML in the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA