Executive brief
Google Chrome for Mac was found to have a security flaw that could allow a local attacker to bypass navigation restrictions. By using a specially crafted malicious file, an attacker could potentially force the browser to navigate to unauthorized locations or bypass security boundaries. This issue is primarily a risk on shared systems where an attacker has local access to the machine.
Technical details
An inappropriate implementation in the Browser component of Google Chrome on macOS allowed a local attacker to bypass navigation restrictions. The vulnerability is triggered when the browser processes a malicious file, leading to a failure in enforcing intended navigation policies. This is classified by Chromium as a Low severity issue. The flaw was addressed in version 151.0.7922.72. While specific root cause details are restricted, it involves local interaction with the filesystem to influence browser navigation state.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Stable channel update released for Mac
- 2026-07-30: disclosed: NVD publication date