Junglewise Threat Intelligence

CVE-2026-11283: Google Chrome navigation restriction bypass in Shortcuts

CVE-2026-11283 · Severity: info · CVSS 3.1 · Published 2026-06-05

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome for macOS could allow a malicious file to bypass standard navigation restrictions. This means an attacker could potentially force the browser to visit unauthorized web addresses or perform unexpected navigation actions if a user interacts with a specially crafted file. This vulnerability primarily affects the 'Shortcuts' feature within the browser on Mac systems.

Technical details

A vulnerability exists in Google Chrome for macOS due to insufficient validation of untrusted input within the Shortcuts component. A remote attacker can exploit this by tricking a user into opening a malicious file, which allows the attacker to bypass established navigation restrictions. This is classified as a navigation bypass vulnerability where the root cause is the failure to properly sanitize input used for browser navigation. The issue is addressed in Chrome version 149.0.7827.53 for Mac.

Affected products

  • Google Chrome prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149.0.7827.53 released for Mac
  • 2026-06-05: disclosed: CVE published in NVD

References

Related threats