Impact
The flaw is an incorrect security UI for file input in Google Chrome that, when a user performs specific gestures on a crafted web page, permits a remote attacker to present a dialog that appears legitimate but is under the attacker’s control. This can enable phishing or other social‑engineering attacks. The weakness is classified as CWE-451 and is rated medium severity by Chromium.
Affected Systems
All releases of Google Chrome prior to version 150.0.7871.47 are affected; no other products or vendors are listed as impacted.
Risk and Exploitability
With a CVSS score of 4.2, the impact is considered medium. The EPSS score is less than 1 %, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a user to visit a malicious page and engage in specific UI gestures, so the risk is largely driven by social‑engineering success rather than technical access.
OpenCVE Enrichment
Debian DLA
Debian DSA