Impact
The flaw arises from an incorrect implementation of the security user interface in Chrome’s WebAppInstalls feature. An attacker can serve a specially crafted HTML page that presents a prompt that looks like a legitimate browser‑initiated installer dialog, enabling UI spoofing. The weakness is identified as CWE‑451.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.46 are affected; version 150.0.7871.46 and later contain the fix.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity vulnerability, and the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to be a remote attacker serving a malicious HTML page that the user opens, which then displays the spoofed installer prompt.
OpenCVE Enrichment
Debian DLA
Debian DSA