Junglewise Threat Intelligence

CVE-2026-17703: Google Chrome for iOS navigation policy bypass

CVE-2026-17703 · Severity: info · CVSS 7.5 · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome for iOS, the popular web browser for iPhones and iPads. This flaw could allow a malicious website to bypass built-in navigation restrictions, potentially leading to unauthorized access to information or redirection to unintended sites. Users are advised to update their browser to the latest version to ensure these protections are enforced correctly.

Technical details

A policy bypass vulnerability exists in Google Chrome for iOS due to insufficient enforcement of navigation restrictions. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass security policies governing how the browser navigates between pages or handles specific URL schemes. This issue was addressed in version 151.0.7922.72. The vulnerability is categorized as 'High' severity by the Chromium project.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-05-30: disclosed: Reported by Google internal team
  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: advisory: NVD publication date

References

Related threats