Impact
The vulnerability is an insufficient policy enforcement in Chrome’s Actor component that allows an attacker to craft a malicious page to bypass navigation restrictions. The flaw represents a CWE‑807 insufficient function level access control and a CWE‑602 external control of critical information that undermines the browser’s ability to enforce navigation policies. An attacker can force the browser to navigate to URLs that should be blocked, which, based on the description, is inferred to facilitate phishing or delivery of malicious content. The weakness carries a medium impact from Chrome's perspective.
Affected Systems
Google Chrome versions prior to 149.0.7827.53 are susceptible. The issue arises only in the stable/enterprise build that includes the Actor component, and it does not affect the underlying OS. Updating to the patched build removes the vulnerability.
Risk and Exploitability
The flaw is exploitable over the network by serving a specially crafted HTML page. Attackers need only get a user to visit the page with a vulnerable Chrome build. The EPSS score, about 0.00016 (<1%), indicates that exploitation is unlikely on a large scale, and it is not listed in the CISA KEV catalog. The CVSS score of 6.5 indicates a medium severity, therefore the risk stays moderate and actionable remediation is advised.
OpenCVE Enrichment
Debian DSA