Impact
The vulnerability arises from an inappropriate implementation within Chrome’s Extensions subsystem that permits a renderer process to display a crafted HTML page designed to mimic the browser’s interface. This flaw, classified as CWE‑451 (copy or forgery), enables a remote attacker who has already compromised the renderer to perform UI spoofing, potentially deceiving users into revealing credentials or other sensitive data. The impact is limited to user deception; it does not provide arbitrary code execution or privilege escalation.
Affected Systems
All users running Google Chrome versions prior to 150.0.7871.47 are affected. Because the flaw requires a prior compromise of the renderer process—such as through a malicious extension or other injected code—the vulnerability only applies in environments where the renderer is already compromised. The affected range is explicitly the software versions listed in the CNA data, but the need for prior compromise is inferred.
Risk and Exploitability
The CVSS score of 4.3 indicates low overall severity, and the EPSS score of <1% suggests exploitation is unlikely. It is not listed in CISA KEV. The vulnerability requires the attacker to first exploit a renderer compromise; once that condition is met, they can execute UI spoofing, but they cannot execute arbitrary code. Therefore the overall risk to un-compromised browsers remains low, but users exposed to a compromised renderer are vulnerable to social‑engineering attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA