Impact
Google Chrome's Network component suffers from insufficient policy enforcement, classified as CWE-602. The flaw allows a threat actor who can serve content from a privileged position on the internal network to create a crafted HTML page that forces the browser to navigate to URLs that the organization has blocked. The vulnerability does not provide code execution and instead bypasses the intended navigation constraints, compromising the policy controls that restrict access to certain web resources.
Affected Systems
All installations of Google Chrome with versions older than 150.0.7871.47 are affected. Google released a fix in update 150.0.7871.47 that removes the insufficient policy enforcement in the Network component. Users should verify that they are running 150.0.7871.47 or later to mitigate this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. This vulnerability is not listed in the CISA KEV catalog. An attacker must be privileged on the internal network to host the malicious page; the attack vector is therefore proximity on a trusted network segment rather than remote exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA