Impact
The flaw resides in Chrome’s navigation input handling. A malicious actor can craft an HTML page that the browser processes, allowing the attacker to circumvent the browser’s site isolation boundaries. This bypass is enabled by an input validation weakness (CWE‑20). The Chromium team labels the severity as medium, reflecting that a successful exploit could let an attacker access or execute code across sites that otherwise run in separate renderer processes.
Affected Systems
All installations of Google Chrome prior to version 150.0.7871.115 on any supported operating system are vulnerable, regardless of the platform or deployment environment.
Risk and Exploitability
Use of a crafted page is required to trigger the vulnerability. The EPSS score of <1% indicates a low likelihood of active exploitation, and the CVSS score of 4.3 is not reflected in the CISA KEV catalog. No public exploits have been documented. While the risk is moderate, the potential to compromise data or code from other sites that share a process makes updating a priority for users.
OpenCVE Enrichment
Debian DLA
Debian DSA