Impact
An improper SplitView implementation in Google Chrome allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by serving a crafted HTML page. This is an Access Control Failure (CWE-284) that lets the browser ignore navigation rules normally enforced, potentially redirecting the user to unintended sites or accessing restricted resources. The Chromium security severity is Medium.
Affected Systems
All installations of Google Chrome older than version 150.0.7871.47 are affected. The weakness resides in the SplitView component of the renderer, so any Chrome instance containing the vulnerable code is at risk until updated.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first compromise the renderer process; once that condition is satisfied, a malicious HTML page can deactivate the navigation restrictions, thereby bypassing the browser’s intended safeguards.
OpenCVE Enrichment
Debian DLA
Debian DSA