Impact
An incorrect handling of the browser History API in Google Chrome allows a remote attacker to display a forged user interface by delivering a specially crafted HTML page. The flaw permits the appearance of legitimate browser UI elements while the content is controlled by the attacker, potentially deceiving users into interacting with malicious content. The vulnerability is identified as CWE‑451.
Affected Systems
All Google Chrome installations older than version 150.0.7871.47, regardless of operating system, are affected. Users who have not applied the June 2026 update remain vulnerable.
Risk and Exploitability
The vulnerability carries a CVSS score of 4.3 and an EPSS score of less than 1 %, indicating a low likelihood of widespread exploitation. The issue is not listed in the CISA KEV catalog. The attack requires the victim to load a malicious page crafted by the attacker, a condition that is inferred from the description but not explicitly stated. Consequently, exploitation relies on the victim’s interaction with the page and on the attacker’s ability to host or distribute it.
OpenCVE Enrichment
Debian DLA
Debian DSA