Impact
Google Chrome on macOS prior to build 150.0.7871.47 contains an improper implementation of its Select component that allows a remote attacker to alter the text shown in the Omnibox (browser address bar) via a crafted HTML page. This flaw, classified as CWE‑451 (Incomplete Verification of Data), does not provide code execution or privilege escalation; it merely changes the visual display of the address bar, potentially misleading users about the site they believe they are visiting.
Affected Systems
All macOS installations of Google Chrome with builds earlier than 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low overall risk, and the EPSS score of less than 1 % shows a low likelihood of active exploitation. The vulnerability is not listed in CISA’s KEV catalog. An attacker who can deliver a malicious HTML page to a user can cause the Omnibox to display incorrect text, but would need the user’s interaction with the crafted page and cannot gain code execution or elevated privileges.
OpenCVE Enrichment
Debian DLA
Debian DSA