Executive brief
A security issue in Google Chrome's Glic component could allow a malicious website to bypass standard navigation restrictions. This means a specially crafted web page could potentially force the browser to navigate to locations or perform actions that should normally be restricted. This could lead to unauthorized interactions with web content or browser features.
Technical details
A navigation restriction bypass vulnerability exists in the Glic component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce security boundaries during browser navigation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass intended navigation constraints, potentially leading to further security policy violations within the browser context. The issue is resolved in Chrome version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome Stable Channel Update for Desktop released version 149.0.7827.53
- 2026-06-04: disclosed: CVE published to NVD dataset