Impact
The vulnerability arises from an inappropriate implementation in the Extensions subsystem of Google Chrome versions earlier than 150.0.7871.47, allowing an attacker who has already gained control of the renderer process to serve a crafted HTML page that mimics the browser’s user interface. This flaw, identified as CWE‑451, does not provide code‑execution privileges but can deceive users into revealing credentials or sensitive information by presenting fake login prompts or other UI elements.
Affected Systems
All users running Google Chrome versions prior to 150.0.7871.47 are affected. The issue requires an existing compromise of the renderer process, so the vulnerability is limited to systems where an extension or malicious content has already executed code within Chrome’s rendering engine.
Risk and Exploitability
The CVSS score of 4.3 indicates low overall severity, and the EPSS score of <1% suggests exploitation is unlikely. The flaw is not listed in the CISA KEV catalog. Because the attacker must first compromise the renderer process, the exploit requires a pre‑existing foothold and does not allow direct remote code execution; thus the overall risk remains low.
OpenCVE Enrichment
Debian DLA
Debian DSA