Impact
An inappropriate implementation in the MediaCapture component of Google Chrome versions prior to 150.0.7871.47 allows a remote attacker who has already compromised the renderer process to use a specially crafted HTML page to alter the rendering of user interface elements. This flaw is described as UI spoofing and is categorized as CWE-451 and CWE-290, indicating improper authentication that can facilitate the misrepresentation.
Affected Systems
Google Chrome released before version 150.0.7871.47 is affected. The issue remains until the browser is updated to 150.0.7871.47 or newer, at which point the flaw is fixed.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, indicating medium severity. The EPSS score of <1% indicates a very low but nonzero probability of exploitation, and the flaw is not listed in CISA's KEV catalog. The likely attack vector requires a remote attacker to first gain control of the renderer process, a nontrivial prerequisite; only then can the attacker present a crafted page to spoof the user interface.
OpenCVE Enrichment
Debian DLA
Debian DSA