Impact
Insufficient policy enforcement in Chrome's isolated web app feature allows a remote attacker to bypass the content‑security‑policy header by serving a crafted HTML page. This flaw is an instance of Improper Limitation of the Impact of an Attack (CWE‑693) and can enable the execution of malicious scripts within an isolated web app context.
Affected Systems
All users running Google Chrome versions earlier than 150.0.7871.47 who use the isolated web app feature on any supported operating system are affected. The vulnerability applies to every isolated web app environment in the browser regardless of platform.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity. The EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector requires a malicious HTML document that a user opens within an isolated web app context to trigger the CSP bypass, making it a remote, content‑based exploit.
OpenCVE Enrichment
Debian DLA
Debian DSA