Impact
The vulnerability arises from insufficient policy enforcement in the Actor component of Google Chrome, allowing a remote attacker to serve a crafted HTML page that forces the browser to navigate to a URL normally blocked by navigation restrictions. The flaw is classified as CWE‑602, indicating a failure to enforce proper bounds on information flow between components. This can lead to unauthorized navigation and potentially expose users to phishing sites or malicious content.
Affected Systems
All users running Google Chrome versions earlier than 150.0.7871.47 on any supported operating system are affected by this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a relatively low likelihood of widespread exploitation. Exploitation requires the attacker to deliver the crafted HTML page to the victim, typically via user interaction or a compromised site; it does not provide code execution, but it enables malicious redirection that can be used for phishing or social engineering.
OpenCVE Enrichment
Debian DLA
Debian DSA