Impact
Insufficient enforcement of the content‑security policy in the Chrome parser allows a remote attacker to serve a specially crafted HTML page that bypasses the page’s CSP restrictions. This weakness is classified as CWE‑693 and can lead to the execution of scripts or loading of resources that would normally be blocked, thereby undermining the intended security controls of the site.
Affected Systems
All Google Chrome releases earlier than version 150.0.7871.47 are affected. The vendor is Google and the product is Chrome.
Risk and Exploitability
The CV4.3 indicates low severity, and the EPSS score is below 1%, indicating a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Based on the description, exploitation requires an attacker to host a malicious page that a user opens in Chrome, a scenario that is feasible over the Internet. No publicly documented exploits are referenced in the provided information. The risk to an organization largely depends on whether strict CSPs are in use, but the issue can be remediated by upgrading Chrome.
OpenCVE Enrichment
Debian DLA
Debian DSA