Impact
In Google Chrome versions prior to 151.0.7922.72, the DevTools implementation contains an inappropriate check that can be exploited to bypass the browser’s navigation restrictions. A remote attacker can craft an HTML page that, when a user performs specific UI gestures, forces Chrome to navigate to an attacker-controlled site, thereby enabling phishing or other malicious activity without granting arbitrary code execution.
Affected Systems
The vulnerability affects Google Chrome, specifically all releases before 151.0.7922.72. Users of these older builds are at risk; no other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate risk, while the EPSS score of less than 1% suggests a very low likelihood of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed public exploitation. Successful exploitation requires user interaction with a crafted page and specific gestures, which raises the barrier but does not eliminate the risk.
OpenCVE Enrichment
Debian DLA
Debian DSA