Impact
Google Chrome's Network component fails to enforce navigation policy, allowing a malicious HTML page served from a privileged internal location to force the browser to navigate to URLs that the organization has blocked. The vulnerability corresponds to CWE-602 and results in a navigation policy bypass. The CVE data indicates it is a medium-severity flaw.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47, on desktop operating systems, are vulnerable.
Risk and Exploitability
The CVSS score of 6.5 indicates medium severity, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the attacker must host the malicious page on an internal network, the attack vector is local, requiring privileged internal access. The impact is limited to bypassing configured navigation restrictions without broader system compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA