Impact
A flaw in Chromium's PermissionsPolicy implementation fails to enforce navigation restrictions, allowing a remote attacker to redirect the browser to URLs that should be blocked. The insufficient policy enforcement permits manipulation of navigation flows and constitutes an access control weakness (CWE‑602).
Affected Systems
Google Chrome installations on the stable channel prior to version 150.0.7871.47 are affected.
Risk and Exploitability
The CVSS score is 6.5, reflecting medium severity, and the EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be carried out over the network from a malicious web page that exploits the deficient PermissionsPolicy enforcement to redirect the user.
OpenCVE Enrichment
Debian DLA
Debian DSA