Impact
A flaw in Chrome’s DevTools policy enforcement allowed a malicious extension that a user installs to bypass navigation restrictions. The vulnerability lets the extension override controls that normally prevent automatic redirects or URL navigation, thereby enabling the delivery of malicious content or phishing payloads. This weakness is an insufficient enforcement of authorization and improper handling of extension privileges.
Affected Systems
Google Chrome versions before 148.0.7778.96 are affected. The issue applies to all desktop installations of Chrome that include the DevTools component, regardless of operating system.
Risk and Exploitability
The CVSS score is 3.1, indicating low severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be persuaded to install a malicious extension, after which the extension can use the DevTools API to bypass navigation controls. The attack vector therefore depends on social engineering and the availability of a user‑installable extension.
OpenCVE Enrichment
Debian DSA