Impact
The flaw arises from an inadequate implementation in the Glic component of Google Chrome that permits a remote attacker to create a crafted HTML page. If a user is persuaded to perform specific UI gestures, the attacker can spoof the browser’s UI, leading the user into interacting with elements that appear legitimate and potentially causing undesired actions. The core weakness is captured by CWE‑451.
Affected Systems
All installations prior to 150.0.7871.47 are affected. The issue has been identified in the stable channel of Chrome. Newer releases contain the fix.
Risk and Exploitability
The CVSS score of 5.3 indicates medium severity, while the EPSS score of < 1% indicates a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires a web‑based crafted page and the victim must perform specific UI gestures such as clicking or dragging. The likely attack vector is web‑based, and while the probability of exploitation is low, the exposure remains limited.
OpenCVE Enrichment
Debian DLA
Debian DSA