Impact
The flaw involves incorrect rendering of Chrome’s security indicators in the TabStrip. A crafted HTML page can cause secure icons to appear for an unsecured connection, misleading users into believing the site is protected. Classified as CWE‑290 and CWE‑451, the vulnerability does not grant code execution or disclosure but enables phishing or social‑engineering attacks by exploiting users’ trust.
Affected Systems
All installations of Google Chrome with revisions earlier than 150.0.7871.47, across Windows, macOS, Linux, and other supported platforms, are affected because the defect is present in the common code base of all released builds before that revision.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity. The EPSS score of less than 1% and the absence of the vulnerability from the CISA KEV catalog suggest a very low likelihood of real‑world exploitation. An attacker can simply host a malicious webpage that a user visits; the attack does not require elevated privileges or code execution, but relies on social‑engineering tactics to coerce users into submitting sensitive information over a page that appears to be secure.
OpenCVE Enrichment
Debian DLA
Debian DSA