Impact
Google Chrome contains an input validation flaw (CWE‑20) that allows a remote attacker to inject arbitrary scripts or HTML through a crafted page. The injected code runs in the victim’s browser context, enabling the attacker to access or modify page content, capture credentials, or perform other malicious actions, thereby compromising the confidentiality and integrity of the user’s environment.
Affected Systems
Google Chrome versions older than 150.0.7871.47 are affected; any build prior to that release is vulnerable.
Risk and Exploitability
The EPSS score is below 1%, indicating a low likelihood of exploitation, while the CVSS score of 6.1 reflects medium severity. The flaw is not listed in the CISA KEV catalog. Exploitation requires a user to open a maliciously crafted HTML page, a scenario that is known. The vulnerability remains a risk until the browser is updated.
OpenCVE Enrichment
Debian DLA
Debian DSA