Impact
An improper implementation of Chrome’s HTMLParser in versions prior to 150.0.7871.47 permits a remote attacker to inject arbitrary scripts or HTML into a crafted web page. This flaw allows cross‑site scripting attacks by failing to isolate malicious markup, enabling the execution of injected code in the context of the victim’s browser.
Affected Systems
All builds of Google Chrome older than 150.0.7871.47 are affected, regardless of the operating system. The vulnerability exists on any Chrome distribution that ships with those versions.
Risk and Exploitability
The EPSS score of less than 1% indicates an extremely low probability of real‑world exploitation, and the flaw is not listed in CISA’s KEV catalog. The CVSS score of 5.4 reflects a medium impact. Based on the description, the most likely attack vector is delivering a crafted page from a malicious website, email link, or attachment. Even so, the low EPSS and medium severity suggest that the overall exploitation risk remains minimal.
OpenCVE Enrichment
Debian DLA
Debian DSA