Junglewise Threat Intelligence

CVE-2026-11257: Google Chrome navigation restriction bypass in Browser

CVE-2026-11257 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in the Google Chrome browser allowed a remote attacker to bypass security restrictions that control how the browser navigates between pages. By tricking a user into visiting a specially crafted website, an attacker could potentially force the browser to navigate to unintended locations or bypass security boundaries. This issue has been resolved in the latest version of Chrome.

Technical details

An inappropriate implementation in the Browser component of Google Chrome allowed a remote attacker to bypass navigation restrictions. The vulnerability is triggered when a user loads a specially crafted HTML page designed by the attacker. This flaw enables the attacker to circumvent intended security boundaries related to page navigation. The issue was identified as having 'Low' severity by the Chromium team and has been patched in version 149.0.7827.53.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
  • 2026-06-05: disclosed: CVE published

References

Related threats