Executive brief
Google Chrome is a widely used web browser. A vulnerability in the PageInfo component could allow an attacker who has already partially compromised the browser's rendering process to bypass security restrictions that normally limit where a user can navigate. This could potentially be used to facilitate further attacks or access restricted content via a specially crafted web page.
Technical details
An improper input validation vulnerability (CWE-20) exists in the PageInfo component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by utilizing a specially crafted HTML page. This is a post-compromise primitive that weakens the browser's sandbox or site isolation boundaries. The issue is addressed in Google Chrome version 150.0.7871.47 and later.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched