Junglewise Threat Intelligence

CVE-2026-17944: Google Chrome for iOS navigation restriction bypass

CVE-2026-17944 · Severity: info · Published 2026-07-30

Technologies: Google Chrome for iOS. Vendors: Google.

Executive brief

Google Chrome for iOS is a mobile web browser. A vulnerability in the way the browser handles page transitions could allow a malicious website to bypass security restrictions that normally control how users navigate between sites. This could potentially lead to users being directed to unintended or malicious content without the browser's standard protections intervening.

Technical details

A navigation restriction bypass vulnerability exists in Google Chrome for iOS due to an inappropriate implementation in the navigation component. By enticing a user to visit a specially crafted HTML page, a remote attacker can bypass security policies that restrict or govern web navigation. This is classified by Chromium as a 'Low' severity issue. The vulnerability is addressed in version 151.0.7922.72 and later. No user interaction beyond visiting the malicious page is specified, though the attack is delivered over the network.

Affected products

  • Google Chrome for iOS prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for desktop and iOS versions.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats