Executive brief
Google Chrome, a widely used web browser, contained a security flaw that could allow a malicious website to bypass intended navigation restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could potentially force the browser to navigate to locations or perform actions that should have been blocked by security policies. This could lead to unauthorized access to internal resources or unexpected browser behavior.
Technical details
A vulnerability classified as insufficient policy enforcement existed in the Network stack of Google Chrome. The flaw allowed a remote attacker to bypass navigation restrictions by utilizing a specially crafted HTML page. The attack vector is network-based and requires the victim to visit a malicious site (user interaction). Successful exploitation allows the attacker to circumvent security boundaries intended to restrict browser navigation. This issue was addressed in Google Chrome version 150.0.7871.47.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: advisory: NVD and Chrome Release blog published the vulnerability details.
- 2026-06-30: patched: Fixed in Chrome version 150.0.7871.47.