Junglewise Threat Intelligence

CVE-2026-11274: Google Chrome for iOS navigation bypass in DOM Distiller

CVE-2026-11274 · Severity: info · CVSS 0 · Published 2026-06-05

Technologies: Google Chrome, Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A security flaw in the DOM Distiller component—which simplifies web pages for easier reading—could allow a malicious website to bypass standard navigation restrictions. This could potentially lead to users being directed to unintended or malicious content without the browser properly enforcing security boundaries.

Technical details

A navigation bypass vulnerability exists in the DOM Distiller component of Google Chrome for iOS prior to version 149.0.7827.53. The flaw stems from an inappropriate implementation that fails to properly enforce navigation restrictions when processing content. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass security boundaries related to page navigation, though the Chromium project classifies the severity of this specific issue as Low. The vulnerability is addressed in the stable channel update for version 149.

Affected products

  • Google Chrome for iOS prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: CVE published

References

Related threats