Impact
Google Chrome contains an input validation error in its navigation handling that permits a remote attacker who has already compromised the renderer process to bypass browser navigation restrictions via a specially crafted HTML document. The flaw is classified as a Medium severity vulnerability (CVSS 6.5). Because the attack requires prior renderer compromise, it does not directly grant new privileges but enables the attacker to force navigation to URLs that would otherwise be disallowed.
Affected Systems
Any installation of Google Chrome running a version earlier than 150.0.7871.125 on a supported desktop platform is affected. The vulnerability is confined to Chrome’s renderer component; other browsers or products are not impacted.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires that an attacker already has a foothold in the renderer process, after which a crafted HTML page can force the browser to navigate to a restricted URL. Given the medium base severity and the prerequisite of renderer compromise, the overall risk for typical environments is moderate, though a determination could vary based on the likelihood of renderer compromise.
OpenCVE Enrichment
Debian DLA
Debian DSA