Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass security warnings or navigation restrictions. This component, known as Safe Browsing, is designed to protect users from visiting dangerous or deceptive websites. If exploited, a user might be directed to a restricted or malicious page without the browser properly blocking the connection or alerting the user.
Technical details
A navigation bypass vulnerability exists in the Safe Browsing component of Google Chrome for iOS. The flaw stems from an inappropriate implementation of security checks when handling specific navigation events. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which allows the attacker to bypass intended navigation restrictions. This could lead to the loading of restricted content or the circumvention of security warnings designed to block malicious URLs. The issue is resolved in version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched