Executive brief
A security vulnerability has been identified in Google Chrome for Android that could allow a malicious website to bypass intended navigation restrictions. This issue affects Glic, a component within the browser, and could be used by an attacker to redirect users to unauthorized or malicious web pages. Users are advised to update their browser to the latest version to mitigate this risk.
Technical details
A vulnerability classified as insufficient policy enforcement exists in the Glic component of Google Chrome for Android. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. This bypass could lead to unauthorized navigation to restricted origins or internal browser states. The issue is addressed in Google Chrome version 151.0.7922.72. Chromium developers have assigned this a Medium severity rating.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched
- 2026-07-30: disclosed