Impact
An improper implementation in Chrome DevTools allows a maliciously crafted extension to perform UI spoofing. The vulnerability, identified as CWE‑451, enables an attacker who persuades a user to install a malicious extension to overlay fake user interface elements, potentially tricking the user into entering sensitive information or accepting actions that would otherwise be disallowed. This weakness does not provide code execution, kernel privilege escalation, or network intrusion; its impact is confined to the visual presentation of the browser UI.
Affected Systems
All users of Google Chrome desktop versions older than 150.0.7871.47 who install extensions are at risk. The flaw is present only in the desktop build up to that specific version and affects the entire set of extensions that run within the Chrome runtime.
Risk and Exploitability
The CVSS score of 4.8 places the vulnerability in the low severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attack execution requires a user to install a malicious extension, typically via social engineering or malicious web content. Based on the description, it is inferred that no special privileges or network access are required; the attack is limited to UI spoofing on the host machine.
OpenCVE Enrichment
Debian DLA
Debian DSA