Impact
The flaw stems from an improper implementation in Chrome DevTools that allows a maliciously crafted extension to perform UI spoofing. The weakness is identified as CWE‑451.
Affected Systems
All users of Google Chrome desktop versions older than 150.0.7871.47 who install extensions are at risk. An attacker who convinces a user to install a malicious extension can trigger this vulnerability.
Risk and Exploitability
The CVSS score of 4.8 places the vulnerability in the low severity range, and the EPSS score of less than 1% indicates a very low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Attack execution requires a user to install a malicious extension, typically via social engineering. No data indicates that special privileges or network access are required, so the attack is limited to UI spoofing.
OpenCVE Enrichment
Debian DLA
Debian DSA