Executive brief
Google Chrome on Android is a mobile web browser used for accessing the internet. A security flaw in the 'Page Info' component could allow a malicious website to bypass certain navigation restrictions. This could potentially lead to unauthorized interactions with web content, though the overall risk is considered low.
Technical details
This vulnerability exists in the Page Info component of Google Chrome on Android prior to version 149.0.7827.53. The flaw is categorized as an inappropriate implementation that allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions. By utilizing a specially crafted HTML page, the attacker can circumvent security boundaries intended to control browser navigation. Google has addressed this issue in the stable channel update for version 149.0.7827.53.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 promoted to stable channel.
- 2026-06-05: disclosed: CVE-2026-11275 published.