Impact
The vulnerability lies in the printing subsystem of Google Chrome; a remote attacker who has already compromised the renderer process can serve a specially crafted HTML page that causes the browser to display user interface elements that do not reflect the real state. This UI spoofing can mislead users into printing malicious content or approving unintended actions, thereby undermining the integrity of the printing interface. The weakness corresponds to CWE‑451, involving information exposure through source spoofing.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.47 are affected, independent of operating system. The flaw resides specifically within the printing component of the browser.
Risk and Exploitability
The CVSS score of 4.3 designates the issue as low severity, and the EPSS score of less than 1 % indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Because the attack requires an attacker to first compromise the renderer process, widespread exploitation is unlikely, but a successful compromise could still result in UI spoofing within the affected session.
OpenCVE Enrichment
Debian DLA
Debian DSA