Impact
The vulnerability arises from an inadequate network implementation within Google Chrome that permits a remote attacker to inject arbitrary scripts or HTML into a page that the browser presents to a user. This UXSS vector allows the malicious code to execute within the victim’s browser session, potentially exposing sensitive data or enabling further malicious interactions. The weakness is categorized as CWE‑79, a form of cross‑site scripting that exploits improper handling of user‑controlled HTML content.
Affected Systems
Google Chrome versions prior to 151.0.7922.72 on all desktop platforms are affected. The flaw resides in the network logic that processes external content before it is rendered in the browser.
Risk and Exploitability
The CVSS score of 6.1 places the vulnerability in the medium severity range, and with an EPSS score of under 1 % it is not a common exploit target. It is not listed in CISA's KEV catalog. The attack vector, while not explicitly documented, is inferred to involve a malicious website or a phishing page that delivers a specially crafted HTML document to the victim’s Chrome browser, which then processes the content and executes the injected scripts.
OpenCVE Enrichment
Debian DLA
Debian DSA