Executive brief
A vulnerability in Google Chrome's navigation component could allow a malicious website to bypass security restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could force the browser to navigate to locations or perform actions that should normally be restricted. This could potentially lead to unauthorized access to web content or minor disruptions in the browsing experience.
Technical details
A vulnerability classified as 'Inappropriate Implementation' exists within the Navigation component of Google Chrome. The flaw allows a remote attacker to bypass established navigation restrictions by enticing a user to visit a maliciously crafted HTML page. This is likely a logic error in how the browser validates or enforces origin/navigation policies during page transitions. The vulnerability is rated as Low severity by Chromium. A fix is available in Google Chrome version 149.0.7827.53 and later.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-04: disclosed: CVE published in NVD dataset