Junglewise Threat Intelligence

CVE-2026-11204: Google Chrome for iOS navigation restriction bypass in Signin

CVE-2026-11204 · Severity: info · CVSS 4.3 · Published 2026-06-04

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for iOS could allow a malicious website to bypass standard navigation restrictions. This means a user visiting a specially crafted webpage might be redirected or navigated to locations that the browser would normally block, potentially interfering with the sign-in process. Users are advised to update their Chrome app to the latest version to maintain standard security protections.

Technical details

A vulnerability classified as an 'Inappropriate Implementation' exists in the Signin component of Google Chrome for iOS. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. While specific root cause details are restricted, the impact involves subverting the browser's intended navigation security logic during sign-in flows. The issue is resolved in version 149.0.7827.53 and later.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-04: disclosed: CVE published

References

Related threats