Impact
An inappropriate implementation in the SplitView component of Google Chrome prior to version 150.0.7871.47 allows a remote attacker to perform UI spoofing via a crafted HTML page. The flaw is based on improper neutralization of input during web page generation (CWE‑451). The result is that UI elements can be overlaid or misrepresented, potentially confusing users about the legitimacy of content and actions presented in the browser.
Affected Systems
All desktop installations of Google Chrome that are earlier than version 150.0.7871.47 are vulnerable. This includes every stable‑channel build released before the update, regardless of operating system. Users who have not applied the latest update are exposed to this flaw.
Risk and Exploitability
The CVSS score is 4.3 and the EPSS score is less than 1 %, indicating a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, and there is no evidence of widespread attacks. The likely attack vector is a malicious web page that a user must open; privileged access or network compromise is not required.
OpenCVE Enrichment
Debian DLA
Debian DSA