Impact
The flaw in Google Chrome’s network layer allows a remote attacker to craft an HTML page that bypasses the browser’s content‑security policy. Because the policy is not enforced, scripts or resources that would normally be blocked can be loaded or executed, compromising the integrity of the displayed content. The weakness corresponds to CWE‑693, a protection mechanism failure.
Affected Systems
Google Chrome desktop releases earlier than version 150.0.7871.47 are affected. Systems running those versions and not yet updated are exposed to the risk.
Risk and Exploitability
The CVSS score is 4.3, indicating low overall severity. The EPSS score is below 1 %, reflecting a very low likelihood of current exploitation. The flaw is not listed in the CISA KEV catalog. The attack vector is remote; an attacker must first entice a user to load a maliciously crafted web page, but no publicly available exploit code is documented. Because the bypass undermines CSP enforcement, it could enable further attacks such as injection of malicious scripts or loading of unauthorized resources, but the CVE description does not explicitly state that arbitrary code execution is achieved.
OpenCVE Enrichment
Debian DLA
Debian DSA