Impact
An improper enforcement of navigation restrictions in Google Chrome versions prior to 149.0.7827.53 allows a remote attacker to bypass navigation controls by delivering a crafted HTML page. This vulnerability can enable the attacker to redirect users to unintended or malicious destinations.
Affected Systems
Google Chrome desktop browsers with build versions earlier than 149.0.7827.53 are affected. The issue applies to any installation that has not received the June 2026 stable channel update.
Risk and Exploitability
The vulnerability is rated with a CVSS score of 4.3, indicating low severity. The EPSS score is less than 1%, reflecting a very low likelihood of exploitation in the wild. It is not listed in the CISA KEV catalog. Based on the description, it can be inferred that the attacker would need to supply a crafted HTML page to a victim, though the exact attack vector is not detailed in the CVE entry.
OpenCVE Enrichment
Debian DSA