Description
Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-04
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inadequate implementation in Page Info in Google Chrome for Android allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by delivering a crafted HTML page. The flaw does not grant arbitrary code execution but permits the attacker to redirect or open URLs the user should not be able to access, potentially facilitating phishing or other deceptive interactions. The impact is largely limited to the compromised renderer’s context and does not directly expose the operating system or other processes. The CVSS score of 6.5 indicates a medium severity for this vulnerability.

Affected Systems

Google Chrome on Android versions prior to 149.0.7827.53 are affected. The vulnerability is present on the Android stable channel and any device running a Chrome installation older than the specified version. No other vendors or product variants are listed.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, and the EPSS score is less than 1%, with the vulnerability not listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation requires the attacker to first compromise the renderer process through a local or privilege‑escalation vulnerability or an elevated app; thus the likely attack vector is a local exploit that enables renderer control. Because of that prerequisite, the attack vector is limited and the likelihood of successful exploitation in the wild remains low. Nonetheless, the presence of this weakness underscores the importance of keeping browsers patched and correctly sandboxed.

Generated by OpenCVE AI on June 7, 2026 at 17:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome on Android to version 149.0.7827.53 or later, which contains the Page Info patch.
  • Ensure automatic updates are enabled on Android to receive future browser security fixes promptly.
  • Limit the use of trusted sites that submit navigation requests to the renderer by restricting site permissions or disabling features that expose Page Info directly.

Generated by OpenCVE AI on June 7, 2026 at 17:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6325-1 chromium security update
History

Mon, 08 Jun 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Google android
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:google:android:-:*:*:*:*:*:*:*
Vendors & Products Google android

Sun, 07 Jun 2026 16:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-862

Sun, 07 Jun 2026 12:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: Insufficient policy enforcement in Page Info
Weaknesses CWE-1021
References
Metrics threat_severity

None

threat_severity

Low


Fri, 05 Jun 2026 22:00:00 +0000

Type Values Removed Values Added
Title Inappropriate Page Info Implementation Allows Navigation Bypass in Chrome on Android

Fri, 05 Jun 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 05 Jun 2026 01:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Fri, 05 Jun 2026 01:15:00 +0000

Type Values Removed Values Added
Title Inappropriate Page Info Implementation Allows Navigation Bypass in Chrome on Android
Weaknesses CWE-862

Thu, 04 Jun 2026 23:45:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Page Info in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-06-05T19:28:39.273Z

Reserved: 2026-06-04T17:11:12.446Z

Link: CVE-2026-11275

cve-icon Vulnrichment

Updated: 2026-06-05T19:28:29.143Z

cve-icon NVD

Status : Analyzed

Published: 2026-06-05T00:17:04.643

Modified: 2026-06-08T14:00:55.590

Link: CVE-2026-11275

cve-icon Redhat

Severity : Low

Publid Date: 2026-06-02T00:00:00Z

Links: CVE-2026-11275 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-06-07T18:00:05Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-284

    Improper Access Control