Executive brief
Google Chrome for iOS is a popular mobile web browser. A security flaw in this version could allow a malicious website to bypass built-in navigation restrictions. This could potentially lead to users being redirected to unintended or malicious sites without their consent.
Technical details
A vulnerability classified as improper input validation (CWE-20) exists in Google Chrome for iOS prior to version 151.0.7922.72. The flaw resides in the handling of untrusted input, which fails to sufficiently validate navigation requests. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page, allowing the attacker to bypass navigation restrictions. This issue is rated as Medium severity by the Chromium project and has been addressed in the stable channel update.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for iOS
- 2026-07-30: disclosed: NVD publication date