Impact
Google Chrome versions earlier than 155.0.8059.39 contain an open redirect flaw in the AppManifest facility. An attacker can craft a malicious HTML page that, when a user clicks a link, redirects the browser to an untrusted site while circumventing Chrome’s origin‑policy checks. The flaw is classified as medium severity by Chromium’s internal scoring, and is a classic example of URL redirection that can be leveraged for phishing or social engineering attacks.
Affected Systems
The vulnerability affects Google Chrome users running any version older than 155.0.8059.39. All operating systems that support this Chrome release are potentially exposed, because the AppManifest redirect logic is identical across platforms.
Risk and Exploitability
No EPSS score is available and the vulnerability is not listed in CISA’s KEV catalog, so publicly documented exploitation data is sparse. The CVSS is not disclosed in the available data, but the medium severity rating indicates a limited but meaningful risk. Exploitation requires the victim to visit a malicious webpage and click a link, which is a common social‑engineering scenario. The attack vector is remote via crafted HTML; an attacker does not need privileged access to the victim’s machine to trigger the redirect.
OpenCVE Enrichment