Junglewise Threat Intelligence

CVE-2026-13818: Google Chrome navigation restriction bypass in Passwords

CVE-2026-13818 · Severity: info · CVSS 7.5 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's password management component could allow a malicious website to bypass standard navigation restrictions. This means an attacker could potentially trick the browser into navigating to pages or performing actions that should normally be restricted. Users are protected by updating to the latest version of the Chrome browser.

Technical details

An inappropriate implementation vulnerability exists in the Passwords component of Google Chrome prior to version 150.0.7871.47. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass navigation restrictions, which could lead to unauthorized page transitions or interaction with browser UI elements that are typically protected. The vulnerability is classified as 'High' severity by the Chromium project. Users should update to version 150.0.7871.47 or later to mitigate this risk.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-05-10: disclosed: Reported to Chromium project by Google internal researchers
  • 2026-06-30: patched: Fixed in Chrome stable channel update 150.0.7871.47
  • 2026-06-30: advisory

References

Related threats