Executive brief
A vulnerability in the TabSwitcher component of Google Chrome on Android could allow a remote attacker to bypass navigation restrictions. This means a malicious website might be able to force the browser to navigate to pages or perform actions that should normally be blocked. While the impact is considered low, it could be used as part of a more complex attack to mislead users or interact with restricted web content.
Technical details
An improper input validation vulnerability (CWE-20) exists in the TabSwitcher component of Google Chrome for Android. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker via crafted network traffic or malicious web content. Successful exploitation allows the attacker to bypass established navigation restrictions within the browser. This issue is fixed in version 150.0.7871.47 and later. Google has classified this with a 'Low' severity rating.
Affected products
- Google Chrome prior to 150.0.7871.47
Timeline
- 2026-06-30: disclosed
- 2026-06-30: patched