Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass standard navigation restrictions. This means a specially crafted web page could potentially redirect users or navigate to internal or restricted pages that should normally be blocked. While the risk is considered low, it could be used as part of a more complex attack to deceive users or access restricted browser functions.
Technical details
An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 150.0.7871.47. The flaw stems from insufficient validation of untrusted input, which allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to trigger navigations that the browser's security policy would otherwise prohibit. This issue is specific to the iOS implementation of the browser. Google has addressed this vulnerability in version 150.0.7871.47.
Affected products
- Google Chrome for iOS prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched
- 2026-06-30: advisory