Impact
The vulnerability is an input validation flaw in Google Chrome on Windows that allows a remote attacker who has already compromised the renderer process to deliver crafted HTML. The attacker can exploit insufficient sanitization of DataTransfer data to cause the browser to render deceptive user interface elements, potentially luring users into unintended actions.
Affected Systems
Google Chrome for Windows is affected. All versions prior to 150.0.7871.47 contain the flaw. The fixed releases, beginning with 150.0.7871.47, validate DataTransfer input correctly.
Risk and Exploitability
The flaw receives a CVSS score of 6.5, indicating medium severity. The EPSS score of <1% suggests a low likelihood of exploitation at present. It is not listed in CISA’s KEV catalog, indicating no known widespread exploitation. Exploitation requires an attacker first to compromise the renderer process; after that, supplied crafted HTML can cause UI spoofing limited to the scope of the renderer and the integrity of the browser’s UI.
OpenCVE Enrichment
Debian DLA
Debian DSA