Impact
Insufficient policy enforcement in DevTools within Google Chrome for Android enables a local attacker to bypass navigation restrictions by opening a malicious file. This flaw, classified as CWE-20, allows the browser to navigate to URLs or resources it is supposed to block. Chromium rates the vulnerability as Medium severity due to its potential impact on user navigation controls.
Affected Systems
All versions of Google Chrome for Android prior to 150.0.7871.47 are affected; devices that do not automatically receive updates remain at risk.
Risk and Exploitability
The CVSS score of 5.5 denotes moderate severity. An EPSS score of less than 1 % indicates a low probability of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitation requires a local attacker to place a crafted file on the device and a user to open that file in DevTools, limiting the attack to local contexts and preventing remote exploitation.
OpenCVE Enrichment
Debian DLA
Debian DSA