Impact
A weakness in Google Chrome's Glic component leads to insufficient policy enforcement, identified as CWE-602. The flaw permits a remote attacker to construct a malicious HTML page that bypasses navigation restrictions normally enforced to block access to certain URLs. Based on the description, it is inferred that the attacker can use the bypass to display content that would otherwise be blocked, potentially enabling further malicious activities.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 are affected.
Risk and Exploitability
Exploitation of a crafted HTML page, which can be delivered by the attacker through phishing or other social‑engineering techniques. The EPSS score of less than 1% indicates a low likelihood of real‑world exploitation, while the CVSS score of 6.5 classifies the flaw as medium severity. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves user interaction with a malicious web page.
OpenCVE Enrichment
Debian DLA
Debian DSA