Executive brief
Google Chrome is a popular web browser used to access the internet and run web applications. A security flaw in the browser's sandbox mechanism could allow a malicious website to bypass navigation restrictions if a user performs specific interactions. This could lead to unauthorized navigation or the circumvention of security policies intended to isolate untrusted web content.
Technical details
A policy bypass vulnerability exists in the IFrameSandbox component of Google Chrome prior to version 147.0.7727.55. The flaw is categorized as a protection mechanism failure (CWE-693) where navigation restrictions can be bypassed. An attacker can exploit this by hosting a crafted HTML page and convincing a user to perform specific UI gestures. Successful exploitation allows the attacker to bypass sandbox-enforced navigation policies. The issue was addressed in the stable channel update for Windows, Mac, and Linux.
Affected products
- Google Chrome prior to 147.0.7727.55
Timeline
- 2026-02-11: other: Reported to vendor
- 2026-04-07: patched: Fixed in version 147.0.7727.55
- 2026-04-08: disclosed: Initial NVD publication