Impact
The flaw is an inappropriate handling of form input in Google Chrome which permits a remote attacker to inject arbitrary scripts or HTML into a web page. When a user opens a crafted page, the unsanitized content is rendered and any injected code runs within the browser context. The impact is that an attacker can execute JavaScript with the permissions of the page, potentially exposing or modifying information displayed to the user.
Affected Systems
Google Chrome builds older than 150.0.7871.115 on the stable channel are affected. The vulnerability applies to all supported operating systems for which the stable desktop build is available.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score of <1% reflects a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector involves an attacker delivering a crafted HTML page that the user subsequently opens; no additional user interaction beyond loading the page is required for the injected code to execute.
OpenCVE Enrichment
Debian DLA
Debian DSA