Impact
An oversight in how Google Chrome processes untrusted input from extensions allows a malicious extension to manipulate the text shown in the Omnibox, the browser’s URL bar. The flaw is an instance of insufficient input validation (CWE‑20). If exploited, a user can be misled into believing they are viewing a trusted site, potentially resulting in credential theft or delivery of fraudulent content.
Affected Systems
Google Chrome browsers on any operating system running a version earlier than 150.0.7871.182 are vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.4, indicating medium severity, and an EPSS score of less than 1%, suggesting a low likelihood of exploitation. It is not listed in CISA KEV. The likely attack vector involves a malicious Chrome extension in combination with a crafted HTML page, inferred from the description; no elevated privileges are required, inferred because the vulnerability is described as affecting untrusted extension input. Exploitation would require a user to visit the crafted page, after which the spoofed URL bar may redirect them to a phishing site or other malicious destination.
OpenCVE Enrichment
Debian DLA
Debian DSA