Impact
The vulnerability stems from an improper implementation in Chrome’s Autofill component that permits a malicious actor to inject arbitrary scripts or HTML into the browser’s user interface, a form of user‑interaction‑based cross‑site scripting (UXSS). When a victim visits a crafted web page, the browser may execute injected code, potentially allowing the attacker to steal credentials, hijack sessions, or perform other malicious actions without requiring elevated privileges. The weakness is classified as CWE‑79, reflecting a failure in input validation allowing script injection.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 are affected. The attack applies to all installations of Chrome running those versions on any supported platform, as the flaw exists in the core browser code common to all builds.
Risk and Exploitability
The CVSS score of 5.4 indicates a medium severity, while the EPSS score of less than 1% shows that current exploitation data is scarce, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote attacker hosting a malicious HTML page that a user visits with Chrome, exploiting the Autofill component to execute arbitrary code. Because the vulnerability does not require local privileges or additional authentication, any user of an affected Chrome build who opens a crafted page could be impacted.
OpenCVE Enrichment
Debian DLA
Debian DSA