Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. By tricking a user into visiting a specially crafted webpage, an attacker could potentially force the browser to navigate to restricted or unintended locations. This could be used to facilitate further attacks or bypass certain security policies designed to protect the user's browsing session.
Technical details
A policy enforcement vulnerability exists in the iOS version of Google Chrome prior to version 150.0.7871.47. The flaw is rooted in how the browser handles navigation requests, failing to strictly enforce security policies when processing certain HTML content. A remote, unauthenticated attacker can exploit this by hosting a specially crafted HTML page and enticing a user to visit it. Successful exploitation allows the attacker to bypass navigation restrictions, potentially leading to unauthorized cross-origin navigations or other security policy violations. Google has addressed this issue in the stable channel update for iOS.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-01-17: disclosed: Reported by researcher 'maitai'
- 2026-06-30: patched: Fixed in version 150.0.7871.47
- 2026-06-30: advisory