Junglewise Threat Intelligence

CVE-2026-13024: Google Chrome input validation bypass in Navigation

CVE-2026-13024 · Severity: info · Published 2026-06-24

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability in Google Chrome's navigation component could allow a malicious website to bypass 'site isolation,' a critical security feature that keeps data from different websites separate. If an attacker has already partially compromised the browser's rendering process, they could use this flaw to access information from other open websites or tabs. This could lead to the theft of sensitive user data, such as login credentials or personal information, from unrelated sites.

Technical details

An improper input validation vulnerability exists in the Navigation component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass Site Isolation protections. By utilizing a specially crafted HTML page, the attacker can circumvent the security boundaries that normally prevent one site from accessing data from another. This vulnerability is categorized as High severity by Chromium. Users are advised to update to version 149.0.7827.197 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 149.0.7827.197

Timeline

  • 2026-05-27: disclosed: Reported to Google by internal researchers
  • 2026-06-23: patched: Stable channel update released for Desktop
  • 2026-06-24: advisory: NVD publication date

References

Related threats