Impact
The vulnerability involves an improper handling of paint operations that can be triggered by a malicious web page. An attacker can craft deceptive UI elements that appear legitimate, potentially misleading users into interacting with malicious content. Since the flaw stems from improper validation of input (CWE‑451), the risk is limited to user deception rather than direct compromise of system integrity or confidentiality.
Affected Systems
Google Chrome browsers on desktop platforms running any version older than 150.0.7871.47 are affected. The Paint component is part of the stable channel; newer releases have removed the vulnerable code paths. Only the older versions of Chrome are susceptible.
Risk and Exploitability
Chromium rates the flaw as in a CVSS 6.5. The EPSS score is below 1% and the vulnerability is not listed in the CISA KEV catalog, indicating a low current exploitation probability. Based on the description, the likely attack vector is a remote crafted web page that a user visits; the attacker does not need local code execution or elevated privileges. The damage is confined to user, so the likelihood of exploitation remains low, though users running older Chrome versions still face a deceptive UI risk.
OpenCVE Enrichment
Debian DLA
Debian DSA