Executive brief
Google Chrome for iOS, a popular mobile web browser, contained a security flaw that could allow a remote attacker to bypass navigation restrictions. By sending malicious network traffic, an attacker could potentially force the browser to navigate to unauthorized or restricted web locations. This could lead to users being directed to malicious sites or bypassing security controls intended to isolate different web sessions.
Technical details
An improper input validation vulnerability (CWE-20) exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw stems from insufficient validation of untrusted input within the browser's navigation component. A remote attacker can exploit this by delivering malicious network traffic to a victim's device, enabling a bypass of established navigation restrictions. This could allow for unauthorized navigation to restricted URLs or the circumvention of security boundaries. The vulnerability has been addressed in the stable channel update 151.0.7922.72.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for iOS.
- 2026-07-30: disclosed: NVD publication date.