Impact
Insufficient policy enforcement in the Chrome parser allows a remote attacker to bypass the content‑security policy by delivering a crafted HTML page. The weakness is classified as CWE‑693 and violates the intended protection of site‑level security headers.
Affected Systems
All Google Chrome releases prior to version 150.0.7871.47 are impacted. The product is Google Chrome.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score is below 1%, suggesting the vulnerability is unlikely to be widely exploited. It is not listed in the CISA KEV catalog. Based on the description, it is inferred that a remote attacker can deliver a malicious page that a user opens in Chrome, a scenario that is feasible over the Internet. Exploitation requires user interaction and does not grant privileges beyond the browser context.
OpenCVE Enrichment
Debian DLA
Debian DSA