Impact
The vulnerability arises from an inappropriate implementation within the Permissions handling of Google Chrome prior to build 150.0.7871.47. It permits a remote attacker to deliver a crafted HTML page that triggers a forged permission request dialog. The deceptive dialog can trick users into granting permissions that would otherwise be denied, causing a UI spoofing attack. This flaw is categorized as CWE-451 and does not provide code execution or denial of service; the impact is purely deceptive UI manipulation.
Affected Systems
Google Chrome builds on the stable channel released before version 150.0.7871.47 are vulnerable. Users who have not yet updated to the patched build are at risk. This includes all desktop deployments of the stable channel that are older than build 150.0.7871.47.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a malicious HTML page delivered to the victim and relies on user interaction; no privileged escalation or credential compromise is needed. The attack vector is remote via a malicious web page, and the flaw is identified as CWE-451.
OpenCVE Enrichment
Debian DLA
Debian DSA