Executive brief
A security issue in Google Chrome's Isolated Web Apps could allow a malicious website to bypass intended navigation restrictions. Isolated Web Apps are designed to provide a more secure, sandboxed environment for specific web applications; this flaw could allow an attacker to force the application to navigate to unauthorized locations via a specially crafted web page. This could potentially lead to users being redirected to malicious sites or interacting with content outside of the app's intended boundaries.
Technical details
An inappropriate implementation vulnerability exists in the Isolated Web Apps (IWA) component of Google Chrome. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, which allows the attacker to bypass navigation restrictions enforced by the IWA framework. The root cause is a failure to properly validate or restrict navigation requests within the isolated context. This vulnerability was addressed in Chrome version 151.0.7922.72. The Chromium project classified this as Medium severity.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date