Impact
The vulnerability originates from an incorrect handling of the security indicators in the Chrome TabStrip. A crafted HTML page can cause the browser to display secure icons for an unsecured connection, leading users to believe a site is protected. This flaw is classified as CWE‑451 and does not provide code execution or data exfiltration but can mislead users about the state of their connection.
Affected Systems
All installations of Google Chrome with revisions earlier than 150.0.7871.47 are impacted. The defect exists in the same code base across the released builds, so every platform version of Chrome before the stated revision remains vulnerable until the update is applied.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as low severity. The EPSS score, being less than 1%, and its absence from the CISA KEV catalog suggest a very low likelihood of real‑world exploitation. An attacker merely needs to host a malicious web page that a user visits. The primary threat is a social‑engineering attack causing users to submit sensitive data over what appears to be a secure connection.
OpenCVE Enrichment
Debian DLA
Debian DSA