Impact
Insufficient policy enforcement in Google Chrome Isolated Web Apps prior to version 150.0.7871.47 lets a remote attacker bypass the content‑security‑policy header by delivering a crafted HTML page. This flaw is an Improper Limitation of the Impact of an Attack (CWE‑693) and can allow the execution of malicious scripts or other unauthorized content within the isolated environment.
Affected Systems
All users of Google Chrome versions earlier than 150.0.7871.47 on any operating system are affected, because the vulnerability applies to every isolated web app environment in the browser regardless of platform.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of <1% suggests a low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it can be inferred that an attacker must supply a malicious HTML document that a user opens within an isolated web app to trigger the CSP bypass.
OpenCVE Enrichment
Debian DLA
Debian DSA