Impact
An inappropriate implementation in Chrome’s TabStrip allowed a remote attacker who could convince a user to perform specific UI gestures to carry out UI spoofing via a crafted HTML page. This weakness corresponds to CWE‑451. The attacker can make the user believe they are interacting with a trustworthy interface while the content is actually a malicious surrogate, potentially leading to phishing, clickjacking or other social‑engineering attacks. The vulnerability does not provide direct code execution or data exfiltration, but it undermines user trust and could enable broader exploitation if coupled with other weaknesses.
Affected Systems
Google Chrome versions prior to 150.0.7871.47 are vulnerable. The affected product is Chrome; any version before the patched release for the stable channel is at risk.
Risk and Exploitability
The CVE is scored as low severity and is not listed in the CISA KEV catalog. Its CVSS score is 4.2. EPSS is not available, indicating no known widespread exploitation. The attack requires the user to be presented with a crafted page and to perform specific gestures, making the exploit opportunistic and user‑dependent. As a result, the probability of exploitation is considered limited, but the impact on user perception and potential for social engineering should not be ignored.
OpenCVE Enrichment
Debian DLA
Debian DSA