Impact
This flaw permits a remote attacker to embed malicious script or HTML – a form of cross‑site scripting – within a crafted HTML page. The vulnerability, classified under CWE‑79, has a CVSS score of 6.1, indicating medium severity. The low EPSS score (less than 1%) reflects a small likelihood of exploitation. If exploited, an attacker could execute code in the victim’s browser context, potentially stealing data, compromising credentials, or performing other malicious actions without user consent.
Affected Systems
All releases of Google Chrome older than version 150.0.7871.47 are impacted. The issue is documented in Google’s Chrome release notes and can be remedied by upgrading to the latest stable release or newer, wherein the affected XML parsing logic has been corrected.
Risk and Exploitability
Exploitation requires the victim to open a maliciously crafted HTML page in Chrome. The attacker’s payload is parsed by the browser’s XML engine, leading to the injection of executable scripts. Because the EPSS score is very low and the vulnerability is not listed in the CISA KEV catalog, the likelihood of real‑world attacks is modest. Nevertheless, the potential for code execution and data theft makes it a notable concern for users who encounter untrusted web content.
OpenCVE Enrichment
Debian DLA
Debian DSA