Executive brief
Google Chrome for Android is a mobile web browser used for accessing the internet. A vulnerability in its developer tools (DevTools) could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. This could potentially lead to unauthorized access to information or unexpected browser behavior when a user visits a specially crafted website.
Technical details
A vulnerability exists in the DevTools component of Google Chrome for Android due to improper input validation. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass navigation restrictions, which are security policies governing how the browser transitions between different origins or contexts. While the CVSS score is 4.3 (Medium), Google has assigned a 'High' internal severity rating. The issue is resolved in version 148.0.7778.96.
Affected products
- Google Chrome prior to 148.0.7778.96
Timeline
- 2026-04-01: disclosed: Reported to Google internally
- 2026-05-05: patched: Stable channel update released
- 2026-05-06: advisory: NVD publication date