Impact
A race condition (CWE‑362) in the history embeddings component of Google Chrome allows a remote attacker to manipulate how the browser displays history entries when a specially crafted HTML page is loaded. The flaw permits the attacker to overwrite or reorder UI elements, making deceptive elements appear as legitimate browser controls, effectively spoofing the interface for the user.
Affected Systems
All installations of Google Chrome before version 150.0.7871.47 are affected, regardless of operating system. The race condition is implemented in the rendering engine shared across platforms, so users on Windows, macOS, Linux, and Chrome OS are all at risk until they upgrade to the fixed release.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of less than 1 % suggests that exploitation is unlikely in the wild. The issue does not provide privilege escalation or remote code execution; it is limited to UI spoofing and potential social‑engineering attacks. The vulnerability is not listed in CISA’s KEV catalog. Exploitation would involve a malicious webpage visiting the victim’s browser; therefore it is considered a remote user‑side attack.
OpenCVE Enrichment
Debian DLA
Debian DSA