Impact
The vulnerability exists in Google Chrome versions prior to 150.0.7871. improper implementation allows a remote attacker to craft a page that triggers navigation of the user to arbitrary URLs without their awareness. The flaw is classified as CWE-284, indicating an improper access control weakness.
Affected Systems
All Google Chrome builds earlier than 150.0.7871.47, regardless of platform. The advisory does not specify any platform restrictions.
Risk and Exploitability
Chromium listed the issue as high severity with a CVSS score of 6.5. The EPSS a very low but non‑zero likelihood of exploitation. The attack vector is remote, using a crafted HTML page to trigger the navigation bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA