Impact
The vulnerability arises from insufficient policy enforcement in the PageInfo component of Google Chrome, identified as CWE-451. The flaw allows a remote attacker to serve a crafted HTML page that mimics browser UI elements, enabling UI spoofing. This can be leveraged for phishing or social engineering but does not provide code execution, data exfiltration, or other direct system compromise.
Affected Systems
Chrome stable channel builds before 150.0.7871.47 are affected. The issue resides within the browser itself, so any operating system running a susceptible version is vulnerable. Users of legacy versions should consider their browsers exposed until updated.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate severity, and the EPSS score of less than 1 % suggests a very low likelihood of observed exploitation. This vulnerability is not listed in CISA’s KEV catalog. A remote attacker would need to supply a malicious web page that contains the crafted content to trigger the spoofing; the attack vector is therefore inferred to be a web‑page load. The weakness involves improperly enforcing policy, which does not allow full code execution or data exfil concern for user deception.
OpenCVE Enrichment
Debian DLA
Debian DSA