Executive brief
A security issue in Google Chrome for iOS could allow a malicious website to bypass standard navigation restrictions. This means a user visiting a specially crafted webpage might be redirected or navigated to locations that the browser would normally block, potentially interfering with the sign-in process. Users are advised to update their Chrome app to the latest version to maintain standard security protections.
Technical details
A vulnerability classified as an 'Inappropriate Implementation' exists in the Signin component of Google Chrome for iOS. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. While specific root cause details are restricted, the impact involves subverting the browser's intended navigation security logic during sign-in flows. The issue is resolved in version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149 promoted to stable channel
- 2026-06-04: disclosed: CVE published