Impact
An inappropriate implementation in the SplitView component of Google Chrome before version 150.0.7871.47 allows a remote attacker to perform UI spoofing via a crafted HTML page. This flaw enables an attacker to overlay or misrepresent browser UI elements, potentially misleading users about the legitimacy of content or actions presented in the browser. The vulnerability is associated with CWE-451, which relates to improper neutralization of content that can lead to unintended display behavior. The published details do not provide the exact code path, and the CWE mapping is based on the impact domain.
Affected Systems
All desktop installations of Google Chrome that are earlier than version 150.0.7871.47 are vulnerable. This includes every stable-channel build released before the update, regardless of operating system. Users who have not applied the latest update are exposed to this flaw.
Risk and Exploitability
The CVSS score of 4.3 and EPSS <1% indicate a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and there is no evidence of widespread attacks. The likely attack vector is a malicious web page that a user must open; privileged access or network compromise is not required.
OpenCVE Enrichment
Debian DLA
Debian DSA