Impact
The vulnerability allows a remote attacker to deliver a specially crafted HTML page that mimics the appearance of an isolated web app, misleading a user into believing the interface is legitimate. Because it is limited to user‑interface deception, it does not provide a path for code execution or data theft.
Affected Systems
All users of Google Chrome versions earlier than 150.0.7871.47 are impacted. The flaw is confined to the Isolated Web Apps component; other browser functions remain unaffected.
Risk and Exploitability
The CVSS base score of 4.3 indicates a low to medium potential impact, and the EPSS score of <1% suggests a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Successful exploitation requires delivering a malicious web page that serves the crafted HTML and a user interacting with the isolated app, making the risk largely a social‑engineering scenario.
OpenCVE Enrichment
Debian DLA
Debian DSA