Impact
Insufficient policy enforcement in Chrome’s Blink rendering engine lets a remote attacker bypass content security policy directives through a specially crafted HTML page. The flaw causes the browser to ignore or incorrectly apply CSP rules, allowing forbidden inline scripts or external resources to be loaded and executed. The result is a loss of integrity of the browsing context, potentially enabling malicious code to run with the victim’s privileges.
Affected Systems
Users running any version of Google Chrome older than 149.0.7827.53 are affected. The vulnerability applies to all platforms covered by the Chrome Stable channel; no distinctions regarding mobile or beta releases are specified in the advisory.
Risk and Exploitability
EPSS score and public CVSS value are not available, and the issue is not in the CISA KEV catalog, indicating no confirmed widespread exploitation. However, the flaw can be triggered by a remote attacker who can serve the crafted HTML page to a victim. The attack vector is inferred to involve a malicious web page presented to the user. While no documented exploit exists yet, the functionality could be abused to inject or execute unauthorized scripts confined to the victim’s browsing session, posing a threat to the integrity of that session.
OpenCVE Enrichment