Impact
A flaw in input validation within Chrome’s DevTools component allows an attacker to craft a malicious file that bypasses the browser’s navigation restrictions. The issue stems from insufficient validation of untrusted input (CWE‑20) and improper handling of file types (CWE434). If exploited, the attacker can cause the browser to load or execute content that would normally be blocked, increasing the risk of further compromise or delivery of unintended payloads. The vulnerability is rated as low severity by the Chromium project, but its effect on user experience and security posture is significant when it is triggered.
Affected Systems
All users running Google Chrome versions prior to 151.0.7922.72 are impacted. The flaw resides specifically in the DevTools component and does not affect other browser functions directly.
Risk and Exploitability
The CVSS score of 6.5 indicates moderate severity, while an EPSS score of less than 1% suggests a very low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying limited observed exploitation. The likely attack vector is that a remote actor provides a malicious file that the victim opens through DevTools, so user awareness and restricted toolbox usage mitigate but do not eliminate risk. Based on the description, it is inferred that exploitation would require the user to intentionally load a file via DevTools, which is a user-initiated action rather than a purely remote attack.
OpenCVE Enrichment
Debian DLA
Debian DSA