Impact
Insufficient validation of untrusted input in Chrome’s PopupBlocker module allows a remote attacker who has already taken control of the browser’s renderer process to craft an HTML page that presents spoofed user‑interface elements. The flaw is an input‑validation weakness (CWE‑20) and is classified by Chromium as a low‑severity issue. The attack would not alter data or compromise the system outside the browser, but it could mislead users by displaying UI elements that look legitimate.
Affected Systems
Google Chrome versions before 150.0.7871.47, regardless of operating system or hardware platform, are affected. The vulnerability exists wherever the renderer component is present.
Risk and Exploitability
Exploitation requires a prior compromise of the renderer process, which reduces the likelihood of a successful attack. The CVSS score of 4.3 indicates low impact, and the EPSS of less than 1% shows that the probability of exploitation is also very low. The flaw is not listed in the CISA KEV catalog and no public exploits have been reported. Nevertheless, if renderer‑level access is obtained, an attacker could use the vulnerability for UI spoofing.
OpenCVE Enrichment
Debian DLA
Debian DSA