Junglewise Threat Intelligence

CVE-2026-13953: Google Chrome navigation restriction bypass in SplitView

CVE-2026-13953 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security flaw in the SplitView component could allow a malicious website to bypass standard navigation restrictions. This means that if a user visits a specially crafted page, an attacker who has already partially compromised the browser's rendering process could force the browser to navigate to unauthorized locations or bypass security boundaries.

Technical details

A vulnerability exists in the SplitView implementation of Google Chrome due to inappropriate logic handling. A remote attacker who has already achieved code execution within a compromised renderer process can exploit this flaw by enticing a user to visit a malicious HTML page. This allows the attacker to bypass navigation restrictions that are normally enforced by the browser's security model. The issue is addressed in Chrome version 150.0.7871.47 and later. Google classifies this as a Medium severity issue.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched
  • 2026-06-30: advisory

References

Related threats