Impact
Insufficient policy enforcement in PageInfo in Google Chrome prior to 150.0.7871.47 allows a remote attacker to perform UI spoofing via a crafted HTML page. The flaw is classified as CWE‑451, pointing to a weakness in information disclosure prevention. The impact is limited to deception of users about the authenticity of browser UI elements; no data loss or arbitrary code execution is directly indicated by the description.
Affected Systems
Google Chrome versions released before 150.0.7871.47 on any operating system are affected. The vulnerability resides solely in the browser application and requires no additional components.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as medium severity, while the EPSS score of less than 1 % reflects a very low likelihood of widespread exploitation. The flaw is not listed in the CISA KEV catalog, indicating no known exploitation. The likely attack vector is a visitor to a crafted web page rendered within the affected browser, requiring user interaction to trigger the UI spoofing.
OpenCVE Enrichment
Debian DLA
Debian DSA