Impact
A flaw in the DevTools component of Google Chrome before version 151.0.7922.72 allows a remote attacker to craft an HTML page that bypasses navigation restrictions. The vulnerability is classified as low severity and, according to the CVE description, does not provide direct remote code execution. The primary impact is that restricted navigation policies can be circumvented, potentially exposing sensitive URLs or resources that would otherwise be blocked by the browser.
Affected Systems
All desktop installations of Google Chrome that are older than version 151.0.7922.72 are affected. The problem applies to any Chrome instance that employs DevTools and encounters a specially crafted HTML page engineered by an attacker.
Risk and Exploitability
The EPSS score of less than 1 % indicates a very low probability of active exploitation, and the vulnerability is not listed in the CISA KEV catalog. With a CVSS base score of 6.5, the overall risk is moderate. The likely attack vector is a remote attacker hosting or delivering a malicious HTML page that exploits the DevTools command handling logic, enabling navigation restriction bypass once the page is opened by a user.
OpenCVE Enrichment
Debian DLA
Debian DSA