Impact
The flaw stems from missing policy enforcement for navigation in Google Chrome’s Actor component, which allowed a remote attacker to deliver a crafted HTML page that bypasses normal navigation restrictions. This weakness is classified as CWE‑602, pointing to an inadequate control over navigation actions. The technical effect is that the browser can be forced to navigate to a URL that would normally be blocked, potentially enabling phishing or other malicious redirection.
Affected Systems
All users running Google Chrome whose version is below 150.0.7871.47 on any supported operating system are affected by this issue.
Risk and Exploitability
The CVSS score of 6.5 indicates a medium severity. The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a comparatively low likelihood of exploitation. Based on the description, the attacker must present the victim with the malicious HTML page, implying that user interaction or a compromised site is required. While the flaw does not give code execution, it enables unauthorized navigation, which could be leveraged for phishing or other social engineering attacks.
OpenCVE Enrichment
Debian DLA
Debian DSA