Impact
The flaw resides in the Downloads component of Google Chrome and permits a remote attacker to craft an HTML page that bypasses Chrome’s navigation restrictions. By loading the page, a malicious user could trigger download‑related navigation actions that Chrome would normally forbid, thereby enabling the attacker to influence or hijack browser navigation. The weakness involves incorrect trust of file URLs (CWE‑358) and inadequate user disclosure for pages loaded from downloads (CWE‑346).
Affected Systems
The vulnerability affects Google Chrome. Specific version details are not listed in the public advisory; however, the issue impacts all Chrome installations that have not applied the security update 149.0.7827.53. No other vendors or products are indicated in the CNA’s notified scope.
Risk and Exploitability
Chromium classifies this issue as Low, with a CVSS score of 5.4, and the EPSS score is less than 1%, indicating a very low exploitation probability. The lack of a known exploit and the low scores suggest the risk remains modest, but environments with permissive download navigation may still be vulnerable.
OpenCVE Enrichment
Debian DSA