Impact
The vulnerability is a UI spoofing flaw classified as CWE‑451 that allows a remote attacker to craft an HTML page that user interface. The flaw is limited to the Isolated Web Apps component, and there is no evidence of additional system impact beyond the potential to mislead users with a forged interface.
Affected Systems
All users running Google Chrome versions older than 150.0.7871.47 are page that targets the Isolated Web Apps component. The issue is confined to this component; other browser functionality is not affected.
Risk and Exploitability
The CVSS base score of 4.3 indicates a low to medium impact, and the EPSS score of <1% suggests a very low likelihood of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a hostile website that serves a crafted HTML page and the user’s interaction with the isolated app, making it largely a social‑engineering scenario. Prompt patching is advised to eliminate this phishing window.
OpenCVE Enrichment
Debian DLA
Debian DSA