Impact
The vulnerability lies in insufficient validation of untrusted input within the PageInfo component of Google Chrome. A remote attacker who has already compromised the renderer process can deliver a crafted HTML page that bypasses navigation restrictions.
Affected Systems
All releases of Google Chrome prior to 150.0.7871.47 are affected; any user running an older build is susceptible, while newer releases include the required input validation fix.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of exploitation, and the CVSS score of 6.5 reflects medium severity. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of the renderer process, which typically arises from a separate vulnerability or a social‑engineered compromise. The description indicates that no independent attack path exists, so it is inferred that initial renderer compromise is mandatory. The overall likelihood of successful exploitation remains low due to this high barrier to initial compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA