Impact
The flaw lies in Chrome’s SplitView rendering, which displays incorrect security information when a user interacts with a malicious page. This enables a remote threat actor to present false indications of a secure connection by manipulating on‑screen gestures. The attack requires specific user interaction and is primarily a deception vector that could mislead users into believing a connection is secure.
Affected Systems
Google Chrome versions older than 150.0.7871.47 on all operating systems that include the SplitView feature are vulnerable.
Risk and Exploitability
The CVSS score of 4.2 classifies this as a low‑severity flaw. The EPSS score indicates a very small exploitation probability (<1%), and the vulnerability is not listed in the CISA KEV catalog. Exploitation would require a user to visit a crafted page that explicitly prompts specific UI gestures, so the likelihood is limited to users with such interaction patterns. The primary risk remains that users could be misled into believing a connection is secure.
OpenCVE Enrichment
Debian DLA
Debian DSA