Description
Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chrome for iOS contains a flaw in policy enforcement that allows a remote attacker to bypass navigation restrictions by serving a crafted HTML page. The issue maps to CWE‑602 and enables the browser to navigate to URLs that would normally be blocked, potentially exposing users to malicious sites. The description indicates that the attacker must supply a malicious HTML page that the user opens, so user interaction is required, which is inferred from the provided details.

Affected Systems

Google Chrome for iOS versions earlier than 150.0.7871.47 are affected; no other operating systems or variants are impacted.

Risk and Exploitability

The vulnerability has a CVSS score of 6.5 and an EPSS score of less than 1%, indicating a low likelihood of exploitation in the wild. It is not listed in CISA’s KEV catalog. The attack requires a malicious HTML page that the user must open, so user interaction is needed. Successful exploitation causes the browser to navigate to previously blocked URLs, which could lead to phishing or other malicious content.

Generated by OpenCVE AI on July 17, 2026 at 15:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update from version 150.0.7871.47 or newer, which fixes the policy enforcement bug (CWE‑602).
  • Verify that Chrome’s navigation restrictions are enabled and that no enterprise policy overrides the default behavior, ensuring policy enforcement cannot be disabled by malicious configuration.
  • If an update cannot be performed or policy settings cannot be controlled, use a different browser or apply iOS content restrictions that block unwanted URLs to mitigate the risk.

Generated by OpenCVE AI on July 17, 2026 at 15:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass in Chrome for iOS via Crafted HTML

Thu, 16 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Crafted HTML Page

Tue, 14 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Crafted HTML Page

Sat, 11 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Restriction Bypass via Crafted HTML Page

Fri, 10 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Restriction Bypass via Crafted HTML Page

Wed, 08 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Crafted HTML Page in Chrome for iOS

Tue, 07 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Crafted HTML Page in Chrome for iOS

Mon, 06 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Policy Enforcement Bypass in Chrome for iOS Allows Navigation to Blocked URLs

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Policy Enforcement Bypass in Chrome for iOS Allows Navigation to Blocked URLs

Sun, 05 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Leading to Remote Navigation Bypass in Chrome for iOS

Sat, 04 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Leading to Remote Navigation Bypass in Chrome for iOS

Fri, 03 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Chrome for iOS

Fri, 03 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Chrome for iOS

Thu, 02 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Crafted HTML

Thu, 02 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Crafted HTML

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Insufficient Policy Enforcement
Weaknesses CWE-284

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Bypass via Insufficient Policy Enforcement
Weaknesses CWE-284

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: High)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T17:44:21.796Z

Reserved: 2026-06-29T23:03:19.648Z

Link: CVE-2026-13795

cve-icon Vulnrichment

Updated: 2026-07-01T17:43:01.970Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:15:16Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security