Impact
The flaw in Chrome's WebAppInstalls component stems from insufficient validation of untrusted input. The likely attack scenario requires an attacker who has already compromised the renderer process, causing Chrome to display a spoofed user interface. This vulnerability is categorized as CWE‑20 (Improper Input Validation).
Affected Systems
All variants of Google Chrome that use the WebAppInstalls feature and are running a build older than 150.0.7871.47 are vulnerable. The defect exists in the renderer component, which is deployed across all supported operating systems and architectures; there are no platform‑specific limitations noted.
Risk and Exploitability
The CVSS score of 4.3 reflects a low severity level, and the EPSS score of less than 1% indicates a very low probability of exploitation. The likely attack vector is a renderer process already compromised, which limits the practical attack surface. The CVE is not listed in the CISA KEV catalog, further suggesting that the overall risk remains low for systems that apply the available update promptly.
OpenCVE Enrichment
Debian DLA
Debian DSA