Impact
Prior to version 150.0.7871.47, Google Chrome implemented PageInfo incorrectly, allowing an attacker who had already breached the renderer process to craft a malicious HTML page that displays counterfeit UI elements. This flaw, classified as CWE‑451, does not enable arbitrary code execution or system compromise but can deceive users into interacting with spoofed interface components within the browser.
Affected Systems
Google Chrome for desktop is affected in all builds released before version 150.0.7871.47. The issue resides in the PageInfo component and applies to every desktop version of Chrome prior to the June 2026 update that introduced the fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, a “Medium” severity rating, and an EPSS score of less than 1 %, indicating a low probability of exploitation in the wild. It is not listed in CISA’s KEV catalog. Exploitation requires that the attacker already has a foothold by compromising the renderer process; therefore, the flaw can only be abused after a prior compromise or through another vulnerability that enables renderer access.
OpenCVE Enrichment
Debian DLA
Debian DSA