Executive brief
A security issue in Google Chrome for macOS could allow a malicious file to bypass standard navigation restrictions. This means an attacker could potentially force the browser to visit unauthorized web addresses or perform unexpected navigation actions if a user interacts with a specially crafted file. This vulnerability primarily affects the 'Shortcuts' feature within the browser on Mac systems.
Technical details
A vulnerability exists in Google Chrome for macOS due to insufficient validation of untrusted input within the Shortcuts component. A remote attacker can exploit this by tricking a user into opening a malicious file, which allows the attacker to bypass established navigation restrictions. This is classified as a navigation bypass vulnerability where the root cause is the failure to properly sanitize input used for browser navigation. The issue is addressed in Chrome version 149.0.7827.53 for Mac.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released for Mac
- 2026-06-05: disclosed: CVE published in NVD