Impact
An inappropriate implementation in the macOS UI handling of Google Chrome allows a remote attacker who convinces a user to perform specific gesture interactions to spoof the user interface through a crafted HTML page. The core weakness lies in improper handling of gesture events, enabling deceptive interface content that can mislead the user into thinking they are interacting with legitimate UI elements.
Affected Systems
The vulnerability affects Google Chrome for macOS prior to version 150.0.7871.47. All users running those builds are at risk.
Risk and Exploitability
The CVSS score of 4.2 indicates a Medium severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, indicating a moderate but non‑immediate threat level. Successful exploitation requires the user to engage in a specific gesture sequence after visiting a malicious HTML page, meaning the attack vector is user‑dependent and not purely automated. Based on the description, it is inferred that the attacker could use social engineering to get a user to perform the required gesture sequence.
OpenCVE Enrichment
Debian DLA
Debian DSA