Executive brief
Google Chrome is a widely used web browser. A security vulnerability in its networking component could allow a remote attacker who has already partially compromised the browser to bypass security restrictions that normally prevent unauthorized navigation. This could lead to further unauthorized access or the ability to circumvent intended security boundaries within the browser.
Technical details
This vulnerability is classified as improper input validation (CWE-20) within the Network component of Google Chrome. The flaw allows a remote attacker to bypass navigation restrictions, provided they have already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can exploit the insufficient validation to navigate to restricted origins or bypass security policies. The issue was addressed in Google Chrome version 150.0.7871.47 for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Release blog published advisory
- 2026-06-30: patched: Fixed in version 150.0.7871.47