Junglewise Threat Intelligence

CVE-2026-11243: Google Chrome navigation restriction bypass in Downloads

CVE-2026-11243 · Severity: info · CVSS 3.1 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's download component could allow a malicious website to bypass certain navigation restrictions. This means a specially crafted webpage might be able to trigger unexpected browser behavior or navigate to locations that should normally be restricted. While the risk is considered low, it could be used as part of a more complex attack to mislead users or interact with downloaded files in unintended ways.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the Downloads component of Google Chrome prior to version 149.0.7827.53. By convincing a user to visit a specially crafted HTML page, a remote attacker can bypass navigation restrictions. This flaw likely stems from insufficient validation of state or origin during download-related navigation events. Successful exploitation allows an attacker to circumvent security boundaries intended to restrict browser navigation, though it is rated as Low severity by Chromium. Users should update to version 149.0.7827.53 or later to mitigate this issue.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-05: disclosed: CVE published

References

Related threats