Executive brief
A vulnerability in Google Chrome's Enterprise features allowed remote attackers to bypass navigation restrictions. This could permit users or malicious sites to access web domains that were intended to be blocked by corporate security policies. Organizations relying on Chrome's URL filtering or navigation controls to manage employee access may have had those protections circumvented.
Technical details
A policy bypass vulnerability exists in the Enterprise component of Google Chrome. The flaw is rooted in how the browser handles navigation restrictions, which could be circumvented by a remote attacker using a specially crafted domain name. This allows for the bypass of administrative URL allowlists or blocklists. The vulnerability affects Google Chrome versions prior to 151.0.7922.72. Users are advised to update to the latest stable channel release to mitigate this issue.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed