Impact
Google Chrome on macOS prior to version 150.0.7871.47 has an incorrect implementation of its Select component that permits a remote attacker to alter the text shown in the Omnibox (address bar) via a crafted HTML page. This vulnerability does not provide a path to arbitrary code execution or privilege escalation; it merely allows the adversary to change the displayed URL in the browser UI.
Affected Systems
The affected product is Google Chrome on macOS before build 150.0.7871.47. No information indicates that Windows or Linux builds are impacted.
Risk and Exploitability
The CVSS score of 4.3 classifies this issue as low overall risk, and the EPSS score is below 1 %. The vulnerability is not included in CISA KEV. The attack requires a remote attacker to host a malicious HTML page; when a user visits that page, the compromised browser updates the Omnobox text, without needing elevated privileges or system access.
OpenCVE Enrichment
Debian DLA
Debian DSA