Impact
Insufficient policy enforcement in Google Chrome allows an attacker who convinces a user to install a crafted extension to bypass the browser’s content security policy. The flaw is identified as CWE-602, reflecting improper client-side handling that permits the extension to execute scripts normally blocked by CSP. This can lead to unauthorized code execution within the user’s browsing context and expose the user to additional attacks.
Affected Systems
Google Chrome versions earlier than 150.0.7871.47, across all distribution channels, are affected by this vulnerability.
Risk and Exploitability
The vulnerability requires social engineering to persuade a user to install a malicious extension, which is inferred from the description that the attacker must convince the user to install. EPSS is below 1% and the vulnerability is not listed in CISA’s KEV catalog, indicating a low probability of widespread exploitation. The CVSS score of 4.3 reflects low severity, but the CSP bypass undermines the browser’s security model and may enable further attacks after the user gains access to a target page.
OpenCVE Enrichment
Debian DLA
Debian DSA