Executive brief
A security issue in Google Chrome for Android could allow a malicious website to bypass certain navigation restrictions. This occurs if an attacker has already partially compromised the browser's internal processing components, allowing them to use a specially crafted webpage to redirect users or access content they should not be able to reach. While the risk is considered low, it could be used as part of a more complex attack to interfere with the user's browsing experience or security boundaries.
Technical details
A vulnerability classified as 'Insufficient policy enforcement' exists in the Navigation component of Google Chrome for Android. The flaw (CWE-20) allows a remote attacker who has already achieved code execution within a compromised renderer process to bypass established navigation security policies. By serving a specifically crafted HTML page, the attacker can force the browser to navigate in ways that should be restricted by policy. This issue was addressed in version 149.0.7827.53. The vulnerability is rated as Low severity by Google because it requires a pre-existing compromise of the renderer process.
Affected products
- Google Chrome prior to 149.0.7827.53
Timeline
- 2026-06-02: patched: Chrome 149.0.7827.53 released to stable channel
- 2026-06-05: disclosed: CVE published