Impact
An improper enforcement of navigation restrictions in Google Chrome versions prior to 149.0.7827.53 allows a remote attacker to craft an HTML page that can override the browser’s security controls and redirect or navigate to unintended or malicious destinations. The primary impact is that a victim’s browsing session can be taken over without the user’s knowledge, potentially exposing the user to phishing, drive‑by download, or other web‑based attacks. The weakness aligns with improper authorization controls (CWE‑285).
Affected Systems
Google Chrome browsers affected are those with build versions earlier than 149.0.7827.53. The vulnerability applies to all Chrome desktop releases that have not applied the patch contained in the June 2026 stable channel update.
Risk and Exploitability
The Chromium security team has labeled the issue as low severity, and the CVE’s EPSS score is not available, indicating limited data on exploitation prevalence. The vulnerability is listed as not part of the CISA KEV catalog. Based on the description, the likely attack vector is an adversary delivering a crafted HTML page to a victim, possibly through phishing or compromised content, to trigger the bypass. No additional prerequisites beyond a user’s browser are specified, suggesting attackability in typical user environments.
OpenCVE Enrichment