I don’t see a CVE for this anywhere. Security folks must be asleep at the wheel /s
I got hacked by pressing F12 then Ctrl+v