Impact
A vulnerability in Google Chrome's navigation module allows a compromised renderer process to bypass navigation restrictions by serving a crafted HTML page. An attacker who gains control of the renderer can redirect the browser to arbitrary URLs, potentially enabling phishing or malicious content delivery. The weakness arises from insufficient validation of untrusted input during navigation, classifying it under CWE‑1286 and CWE‑20. While the vulnerability does not allow remote code execution directly, it can undermine content security and user trust through navigation hijacking.
Affected Systems
Affected systems are users running Google Chrome on any platform where the browser version is older than 151.0.7922.72. The update that fixed the issue is announced for the stable channel and is available in all supported operating systems. No other Chrome releases or versions are documented as affected.
Risk and Exploitability
The baseline CVSS score of 6.5 indicates a medium severity, and the EPSS score of less than 1% shows a very low probability of exploitation in the wild. The vulnerability requires that the attacker have already compromised the renderer process before the navigation bypass can be executed, imposing a precondition that limits the attack surface. The vulnerability is not listed in the CISA KEV catalog, implying no known widespread exploitation. Nonetheless, organizations should treat this as a medium‑risk issue if they rely on strict navigation controls.
OpenCVE Enrichment
Debian DLA
Debian DSA