Impact
In Google Chrome versions prior to 149.0.7827.53 the Link Preview component contains an inappropriate implementation that allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by delivering a specially crafted HTML page. The flaw reflects improper target validation and access control weaknesses described by CWE-1021, CWE-284, enabling the renderer to follow URLs that should otherwise be blocked.
Affected Systems
All users running Google Chrome desktop before version 149.0.7827.53 are affected. No other Google products or third‑party applications are impacted by this issue.
Risk and Exploitability
Chromium assigns this defect a CVSS score of 6.5, placing it in the medium severity range. The EPSS score is below 1%, indicating a low likelihood of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Exploitation requires the attacker first to compromise the renderer process, after which a crafted HTML page can be served from any site the user visits to force navigation beyond the intended restrictions.
OpenCVE Enrichment
Debian DSA