Impact
An improper HTML parsing implementation in Chrome prior to 150.0.7871.47 and execute arbitrary scripts or HTML through a specially crafted web page, enabling cross‑site scripting attacks. The flaw stems from a failure to properly isolate malicious markup, allowing injection of arbitrary scripts or HTML. This vulnerability is a typical instance of a web application weakness that can lead to XSS.
Affected Systems
Google Chrome versions older than 150.0.7871.47 are affected; the vulnerability exists on any build of Chrome that ships those versions, regardless of the operating system.
Risk and Exploitability
The EPSS score of < 1% indicates an extremely low probability of exploitation, and the flaw is not listed in CISA's KEV catalog. The CVSS score of 5.4 reflects a medium impact. Based on the description, it is inferred that the most likely attack vector is delivering a crafted page via a malicious website, an email link, or a malicious attachment. Even so, the combination of a low EPSS and medium severity suggests that the real‑world exploitation risk is minimal.
OpenCVE Enrichment
Debian DLA
Debian DSA