Executive brief
Google Chrome for iOS is a popular mobile web browser. A security flaw was identified where a malicious website could trick a user into performing specific touch gestures to bypass security restrictions that normally prevent unauthorized navigation. This could allow a site to redirect users to unintended or malicious locations against the browser's security policies.
Technical details
An improper input validation vulnerability (CWE-20) exists in the iOS implementation of Google Chrome. The flaw allows a remote attacker to bypass navigation restrictions by convincing a user to perform specific UI gestures on a maliciously crafted HTML page. This bypass occurs because the browser fails to sufficiently validate input during certain navigation events triggered by user interaction. The vulnerability is addressed in version 150.0.7871.47. An attacker could use this to force the browser to navigate to restricted origins or bypass security boundaries intended to isolate web content.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched