Impact
Google Chrome versions before 151.0.7922.109 contain insufficient policy enforcement in the navigation component. When a remote attacker has already compromised the renderer process, a crafted HTML page can trigger a privilege escalation that potentially bypasses the browser sandbox and allows code execution outside the intended confinement. This flaw corresponds to CWE-266 and CWE-693, reflecting an inadequate enforcement of navigation policy controls and an authorization bypass through user-controlled privileges, leading to an elevation of privilege for the attacker within the browser process.
Affected Systems
The vulnerability affects Google Chrome running on any platform that includes the renderer process. All installations of Chrome prior to version 151.0.7922.109 are susceptible; no partial or selective component impact is reported.
Risk and Exploitability
This vulnerability, classified as CWE-266 and CWE-693, indicates an authorization bypass and access control deficiency due to insufficient navigation policy enforcement. The CVSS score of 8.3 indicates high severity and significant impact. The EPSS score is < 1%, which suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at this time. However, the exploit path requires an initial compromise of the renderer process, which could arise from a broader compromise or from malicious web content. The likely attack vector involves a remote attacker delivering malicious HTML that exploits the navigation policy loophole once the renderer process is already breached.
OpenCVE Enrichment
Debian DLA
Debian DSA