Junglewise Threat Intelligence

CVE-2026-11018: Google Chrome navigation restriction bypass in Actor

CVE-2026-11018 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. By tricking a user into visiting a specially crafted webpage, an attacker could force the browser to navigate to locations that should otherwise be restricted. This could be used to facilitate further attacks or bypass certain web-based security policies.

Technical details

A policy enforcement vulnerability exists in the 'Actor' component of Google Chrome. The flaw allows a remote attacker to bypass intended navigation restrictions by utilizing a specially crafted HTML page. This is classified as a navigation restriction bypass, which typically occurs when the browser fails to properly validate or enforce security boundaries during page transitions or frame interactions. An attacker would need to entice a user to visit a malicious website to trigger the exploit. The issue is resolved in Google Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-04: disclosed: CVE published by NVD

References

Related threats