Impact
Google Chrome prior to 149.0.7827.53 contains an input‑validation flaw in the DevTools component that allows an attacker who has persuaded a user to install a malicious extension to bypass normal navigation restrictions. The defect permits the extension to craft input that the browser treats as trusted, effectively granting it elevated privileges within the context of the user’s session. The CVSS score of 6.5 classifies the issue as medium severity.
Affected Systems
Google Chrome versions earlier than 149.0.7827.53. Users of the stable channel with these releases should be aware that any extensions installed from the web can exploit this flaw.
Risk and Exploitability
Because the vulnerability requires the user to install an extension, the attack vector is user interaction through social engineering or deceptive installation prompts. Once the malicious extension runs in the browser, it can navigate the user to arbitrary URLs or perform actions that normally trigger navigation restrictions, potentially exposing sensitive web content or data. With an EPSS score of < 1%, the likelihood of exploitation is very low; the vulnerability is not listed in CISA’s KEV catalog, indicating no confirmed exploits yet, but the ease of extension installation suggests that it could be abused if users trust the extension source.
OpenCVE Enrichment
Debian DSA