Impact
Insufficient policy enforcement in Google Chrome’s networking component allows a remote attacker to serve a malicious HTML page that causes the browser to navigate outside user‑defined navigation restrictions. This flaw is classified as CWE‑602, indicating missing policy enforcement for navigation restrictions. The impact is that users may be redirected to deceptive or harmful destinations, compromising the integrity of browsing sessions.
Affected Systems
All installations of Google Chrome released before version 150.0.7871.47 on supported operating systems are susceptible, regardless of platform.
Risk and Exploitability
The CVSS score of 4.3 indicates a low overall severity, and the EPSS score of less than 1% indicates a modest likelihood of exploitation in the wild catalog. A remote attacker can trigger the flaw by hosting a malicious page without needing elevated privileges or local access, keeping the attack surface broad while confining the impact to the navigation state of an affected user.
OpenCVE Enrichment
Debian DLA
Debian DSA