Impact
The Skia renderer in Google Chrome prior to version 150.0.7871.46 contains an inappropriate implementation that allows a remote attacker who has already compromised the renderer process to perform UI spoofing via a crafted HTML page. The weakness is identified as CWE‑451.
Affected Systems
Google Chrome versions earlier than 150.0.7871.46 on any supported platform are affected. The issue resides solely in the Skia rendering component, so only the Chrome binaries that include the older Skia code are vulnerable.
Risk and Exploitability
The CVSS score of 4.3 and an EPSS of less than 1 % indicate that the overall risk is low. The vulnerability is not listed in CISA’s KEV catalog, further suggesting limited exploitation activity. However, an attacker must first compromise the renderer before UI spoofing can be performed, which requires a separate compromise step.
OpenCVE Enrichment
Debian DLA
Debian DSA