Impact
An inappropriate implementation in the WebAppInstalls feature of Google Chrome for Windows permits a remote attacker, by tricking a user into executing defined UI gestures on a malicious web page, to perform UI spoofing. This flaw does not grant code execution or direct data theft; it merely allows manipulation of the interface to mimic legitimate prompts or buttons, potentially misleading the user. The vulnerability is categorized under CWE‑451 and carries a CVSS score of 4.2, indicating limited impact and a requirement for user interaction.
Affected Systems
Windows installations of Google Chrome with a build before version 150.0.7871.47 are affected. Any user running any of these historical builds could be vulnerable – versions newer than 150.0.7871.47 contain the fix.
Risk and Exploitability
Exploitation requires an attacker to host a malicious page and persuade the user to perform specific gestures, such as clicking or swiping. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, no widespread exploitation trends are known. The CVSS rating of 4.2 and lack of publicly documented exploits suggest a moderate threat level, mainly limited to targeted phishing or social engineering efforts. Updating the browser or disabling the Web App Installs feature mitigates the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA