Impact
Insufficient policy enforcement in Chrome DevTools prior to version 146.0.7680.71 allows a remote attacker to bypass navigation restrictions using a crafted HTML page, potentially redirecting users to malicious sites or exfiltrating data. The flaw is classified as CWE-602, reflecting improper enforcement of privilege limits. The impact is the ability to navigate to arbitrary URLs without the user’s explicit consent.
Affected Systems
Google Chrome versions before 146.0.7680.71 on Windows, macOS, and Linux are affected. All builds of Chrome that include the DevTools component and lack the updated policy enforcement pose the risk.
Risk and Exploitability
The vulnerability receives a CVSS score of 4.3 (Low) and an EPSS score below 1%, indicating rare exploitation. Based on the description, it is inferred that the likely attack vector is remote: a malicious user can craft a webpage that opens DevTools and inputs a navigation command to redirect the browser. There is no requirement for additional privileges, and the flaw is not listed in CISA’s KEV catalog. Overall risk remains low, but it is still advised to remediate.
OpenCVE Enrichment
Debian DSA