Executive brief
A security issue in Google Chrome for Android could allow a malicious website to bypass standard navigation restrictions. This means a specially crafted web page might be able to trigger navigations that the browser would normally block, potentially leading to unexpected behavior or unauthorized access to other web content. Users are advised to update their mobile browser to the latest version to maintain security.
Technical details
A vulnerability classified as an 'inappropriate implementation' exists within the Session component of Google Chrome for Android. A remote attacker can exploit this flaw by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass navigation restrictions, which are security boundaries intended to control how and where the browser navigates. This issue is fixed in version 151.0.7922.72. The vulnerability is rated as Low severity by Chromium.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed