Junglewise Threat Intelligence

CVE-2026-11017: Google Chrome navigation restriction bypass in Link Preview

CVE-2026-11017 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Link Preview feature could allow an attacker to bypass security restrictions that control how the browser navigates between pages. To exploit this, an attacker would first need to compromise the browser's rendering process, typically by tricking a user into visiting a malicious website. Successful exploitation could allow the attacker to force the browser to navigate to unauthorized locations or bypass intended security boundaries.

Technical details

This vulnerability is classified as an inappropriate implementation within the Link Preview component of Google Chrome. The flaw resides in how the browser handles navigation logic for previews, failing to strictly enforce navigation restrictions. An attacker who has already achieved code execution within a compromised renderer process can leverage this flaw by serving a specially crafted HTML page. This allows the attacker to bypass security boundaries that normally restrict page transitions or origin-based navigation. The issue was addressed in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-04: disclosed: CVE-2026-11017 published.

References

Related threats