Impact
The vulnerability exists in Google Chrome versions prior to 150.0.7871.47, where an improper implementation of password navigation restrictions allows a remote attacker to craft an HTML page that causes the browser to ignore these restrictions and navigate the user to arbitrary URLs without their awareness. The flaw is classified as CWE‑284, indicating an improper access control weakness.
Affected Systems
All Google Chrome builds earlier than 150.0.7871.47, regardless of. The advisory does not specify any platform restrictions.
Risk and Exploitability
Chromium listed the issue as high severity with a CVSS score of 6.5. The EPSS score is less than 1 %, indicating a very low but non‑zero likelihood of exploitation. The attack vector is remote; an attacker only needs to host or serve a crafted page to trigger the navigation bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA