Impact
Google Chrome implements navigation restrictions that prevent certain URLs from being accessed directly. An insufficient policy enforcement in the Glic component before version 150.0.7871.47 allowed a remote attacker to serve a crafted HTML page that caused the browser to ignore those restrictions. The flaw is identified as an improper authority check (CWE-602), enabling the attacker to deliver content normally blocked by the browser’s navigation policy.
Affected Systems
All installations of Google Chrome running a version earlier than 150.0.7871.47 are vulnerable. This includes stable channel users and any builds derived from the affected code base. Versions 150.0.7871.47 and later include the enforcement fix.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.5, categorizing it as medium severity. The EPSS score is reported as less than 1%, indicating a low probability of exploitation, and it is not listed in CISA’s KEV catalog. An attacker can exploit the flaw by hosting a malicious HTML page, luring a user to visit that page, and causing the browser to override navigation restrictions without requiring any local privileges or code execution. The outcome is unauthorized access to sites or data that should have been blocked by the browser’s policy.
OpenCVE Enrichment
Debian DLA
Debian DSA