Junglewise Threat Intelligence

CVE-2026-11248: Google Chrome navigation restriction bypass in Google Lens

CVE-2026-11248 · Severity: info · CVSS 2 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Lens within the Google Chrome browser could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. This could potentially lead to unauthorized navigation or interactions within the browser interface. Users are advised to update to the latest version of Chrome to mitigate this risk.

Technical details

A navigation restriction bypass vulnerability exists in the Google Lens component of Google Chrome. The flaw stems from an inappropriate implementation that fails to properly enforce security boundaries during certain navigation events. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass intended navigation restrictions, though the impact is categorized as low severity by Chromium. The issue is resolved in Chrome version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel.
  • 2026-06-05: advisory: NVD published the CVE record.

References

Related threats