Impact
Insufficient policy enforcement in Glic, a component of Google Chrome for Android, allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. The flaw does not provide direct code execution; instead it permits an attacker to trick the browser into visiting a malicious site or performing a navigation action that normally would be blocked. This weakness is classified as CWE-602, indicating insufficient policy enforcement. The vulnerability is classified as medium severity by the Chromium security team, reflecting the potential for phishing or unintended navigation but no immediate denial of service or data disclosure.
Affected Systems
Google Chrome on Android versions earlier than 151.0.7922.72 are affected. Users running those builds are vulnerable; the issue is fixed in the stated release 151.0.7922.72 and later.
Risk and Exploitability
The EPSS score is less than 1% and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low overall exploitation probability. The CVSS score of 6.5 indicates medium severity. The likely attack vector is via a user opening a maliciously crafted web page or visiting a site that serves such content; no additional privileges or network access are required. Given the mild exploitation likelihood and the non-destructive impact, the risk is moderate but still actionable.
OpenCVE Enrichment
Debian DLA
Debian DSA