Impact
A flaw in WebGL handling within Google Chrome before version 150.0.7871.115 allows an attacker to inject arbitrary scripts or HTML via a crafted webpage. This injection enables the execution of malicious code directly in the victim’s browser context while the user interacts with the page.
Affected Systems
All users of Google Chrome whose browser version is earlier than 150.0.7871.115 are affected. The vulnerability applies specifically to the Chrome product distributed by Google.
Risk and Exploitability
The likely attack vector is delivering a maliciously crafted HTML page to a user, as inferred from the description that a remote attacker can inject scripts via a crafted page. The vulnerability can be triggered remotely by visiting such a page; no user credentials or special access are required beyond a standard web visit. The EPSS score is < 1%, indicating a very low probability of exploitation. The CVSS score of 6.1 reflects medium severity. The flaw is not listed in CISA’s KEV catalog. Any user browsing the page could be impacted.
OpenCVE Enrichment
Debian DLA
Debian DSA