Impact
A vulnerability exists in the SplitView component of Google Chrome that allows an attacker who has already compromised the renderer process to manipulate navigation rules through a specifically crafted HTML page. This flaw, classified as a privilege escalation (CWE‑284), lets the compromised renderer ignore navigation restrictions that the browser would normally enforce, potentially allowing the user to be redirected to unintended sites.
Affected Systems
Google Chrome installations running any versions prior to 150.0.7871.47 are susceptible, regardless of the operating system. The flaw resides in the renderer, so any Chrome instance deploying that code is at risk until the software is updated to the patched release or newer.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to initially compromise the renderer process; once that condition is met, a malicious HTML page can deactivate navigation restrictions, thereby bypassing the browser's intended controls.
OpenCVE Enrichment
Debian DLA
Debian DSA