Executive brief
Google Chrome, a widely used web browser, was found to have a security flaw in its navigation component. An attacker who has already partially compromised the browser's internal rendering process could use this vulnerability to bypass security restrictions that normally prevent unauthorized navigation. This could allow an attacker to force the browser to visit malicious sites or access restricted content, potentially leading to further data exposure or system compromise.
Technical details
An improper input validation vulnerability (CWE-20) exists in the Navigation component of Google Chrome. The flaw allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by utilizing a specially crafted HTML page. This is a multi-stage attack requiring an initial compromise of the renderer sandbox. The vulnerability was addressed in Google Chrome version 150.0.7871.125 for Windows and Mac, and 150.0.7871.124 for Linux.
Affected products
- Google Chrome Prior to 150.0.7871.125
Timeline
- 2026-05-16: disclosed: Reported to Google by internal researchers
- 2026-07-14: patched: Stable channel update released
- 2026-07-14: advisory: NVD publication date