Impact
The flaw is an inappropriate implementation within Chrome’s printing subsystem that allows an attacker who has already compromised the renderer process to serve a crafted HTML page that causes the browser to display misleading graphical elements in the print preview or other UI contexts. This issue is classified as CWE-451 and results in UI spoofing, undermining the integrity of the printing UI.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1% shows a low probability of exploitation at the time of assessment. There is no evidence of reported exploitation, and the vulnerability is not listed in the CISA KEV catalog. It is inferred that because the flaw requires a prior compromise of the renderer process, widespread exploitation is unlikely.
OpenCVE Enrichment
Debian DLA
Debian DSA