Impact
The flaw stems from inadequate validation of untrusted network input in Chrome’s Network component, a classic example of an input validation weakness (CWE‑20). An attacker who has already gained control of the renderer process can serve a crafted HTML page that displays a spoofed user interface; the result is a deceptive UI that may cause users to interact with content they believe to be legitimate, potentially creating confusion or unintended actions.
Affected Systems
Google Chrome browsers running versions earlier than 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score of 4.3 classifies the issue as low severity, and the EPSS score of less than 1% indicates a very low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires an attacker to first compromise the renderer process; after that, a malicious HTML page can be used for UI spoofing. Consequently, the attack vector is not purely remote and would occur only when the attacker can execute malicious code within the browser environment.
OpenCVE Enrichment
Debian DLA
Debian DSA