Junglewise Threat Intelligence

CVE-2026-11297: Google Chrome for Android navigation bypass in Reader Mode

CVE-2026-11297 · Severity: info · CVSS 2 · Published 2026-06-05

Technologies: Google Chrome for Android. Vendors: Google.

Executive brief

A security issue in Google Chrome for Android's Reader Mode could allow a malicious file to bypass standard navigation restrictions. Reader Mode is a feature that simplifies web pages for easier reading. In practice, a local attacker could use this flaw to force the browser to navigate to unauthorized locations or bypass security boundaries intended to keep different web content separated.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Reader Mode component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input when processing files within Reader Mode. A local attacker can exploit this by providing a specially crafted malicious file to bypass navigation restrictions. This could potentially allow the attacker to circumvent security boundaries that normally restrict page transitions or origin-based access. The vulnerability is addressed in version 149.0.7827.53.

Affected products

  • Google Chrome for Android prior to 149.0.7827.53

Timeline

  • 2026-06-02: patched: Chrome 149 promoted to stable channel
  • 2026-06-05: disclosed: NVD publication date

References

Related threats