Executive brief
A vulnerability in Google Chrome for iOS could allow a malicious website to bypass standard navigation restrictions. This means a specially crafted web page could potentially redirect users or navigate to content that should otherwise be restricted by the browser's security policies. While rated as low severity, it affects the browser's ability to enforce boundaries between different web locations.
Technical details
A navigation restriction bypass vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the browser's navigation handling logic. By enticing a user to visit a specially crafted HTML page, a remote attacker can trigger a bypass of security restrictions that govern how the browser transitions between different web origins or internal pages. The vulnerability is classified by Chromium as 'Low' severity and was addressed in version 151.0.7922.72. No evidence of exploitation in the wild was reported at the time of disclosure.
Affected products
- Google Chrome for iOS prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date