Impact
The vulnerability resides in Chrome’s handling of CSS and enables a remote attacker to inject arbitrary scripts or HTML through a crafted webpage. Such code execution occurs within the browser context, potentially compromising user data and allowing further malicious activity. The weakness is classified under CWE‑79.
Affected Systems
Google Chrome on any platform – all releases earlier than version 151.0.7922.72 are affected.
Risk and Exploitability
The CVSS score of 6.1 indicates medium severity, while the EPSS of less than 1% suggests exploitation is currently rare but possible. The vulnerability is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by delivering a specially crafted HTML page, typically by convincing a user to visit or embed content from a malicious website. No special privileges are required beyond normal user interaction with the browser.
OpenCVE Enrichment
Debian DLA
Debian DSA