Executive brief
A security vulnerability has been identified in the PDF component of Google Chrome. This flaw could allow a remote attacker who has already partially compromised the browser's rendering process to bypass security restrictions that normally prevent unauthorized navigation. In a real-world scenario, this could be used to direct a user's browser to malicious websites or bypass internal security boundaries, potentially leading to further exploitation or data exposure.
Technical details
This vulnerability is classified as insufficient data validation within the PDF engine of Google Chrome. The flaw exists in versions prior to 150.0.7871.47. An attacker who has already achieved code execution within a compromised renderer process can exploit this issue by using a specially crafted HTML page to bypass navigation restrictions. This is a post-compromise primitive that allows an attacker to escape certain sandbox-enforced navigation policies. The issue was addressed in the Stable Channel update to version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory
- 2026-06-30: patched