Impact
An inappropriate implementation in the Media component of Google Chrome for Android allows a remote attacker to bypass navigation restrictions via a crafted HTML page. The flaw represents a broken access control weakness (CWE‑284) and a missing access control for privileged functions (CWE‑1021). Although it does not provide code execution or denial of service, it permits the browser to navigate to URLs that would normally be disallowed.
Affected Systems
Google Chrome for Android versions prior to 151.0.7922.72 are affected. The issue appears in the mobile release; later stable channel builds are not impacted.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and the EPSS score of <1% signifies a very low probability of exploitation. The vulnerability is not listed in CISA's KEV catalog. Based on the description, the likely attack vector is a malicious web page or content provider that delivers a crafted HTML page to a user’s Chrome for Android, where the Media component is exploited to bypass navigation restrictions.
OpenCVE Enrichment
Debian DLA
Debian DSA