Description
Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An inappropriate implementation of Safe Browsing in Google Chrome for iOS allows a remote attacker to bypass browser navigation restrictions by serving a crafted HTML page. The flaw permits the attacker to redirect a user to untrusted destinations, enabling phishing, drive‑by downloads, or other malicious content delivery. The underlying weakness is a failure to enforce navigation controls, identified as CWE‑693.

Affected Systems

All Google Chrome for iOS releases older than 150.0.7871.47 are affected. Users running any of those older versions on iOS devices are vulnerable because Safe Browsing does not correctly enforce navigation restrictions.

Risk and Exploitability

The CVSS score of 6.5 indicates medium severity. The EPSS score is < 1% and the issue is not listed in the CISA KEV catalog, indicating limited known exploitation. Based on the description, it is inferred that a remote attacker could exploit the flaw by delivering a crafted HTML page that bypasses Safe Browsing navigation restrictions, potentially leading to phishing or drive‑by downloads. Chrome’s widespread use could expose many users, but the low EPSS suggests exploitation is not yet widespread, resulting in a moderate overall risk.

Generated by OpenCVE AI on July 15, 2026 at 10:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to 150.0 or later
  • Configure mobile device management to allow only the patched Chrome version and block installation of older releases
  • Instruct users to check the destination of redirects before clicking or disable automatic link opening in Chrome if practical

Generated by OpenCVE AI on July 15, 2026 at 10:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Tue, 14 Jul 2026 01:30:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Mon, 13 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Sun, 12 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Google Chrome for iOS

Thu, 09 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Google Chrome for iOS

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Navigation Restriction Bypass via Crafted HTML

Wed, 08 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Navigation Restriction Bypass via Crafted HTML

Tue, 07 Jul 2026 10:45:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Navigation Bypass

Mon, 06 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome iOS Safe Browsing Navigation Bypass

Sun, 05 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Sun, 05 Jul 2026 07:15:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Google Chrome for iOS

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Google Chrome for iOS

Fri, 03 Jul 2026 20:15:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Chrome for iOS

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Chrome for iOS

Thu, 02 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Thu, 02 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass in Chrome for iOS

Thu, 02 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Safe Browsing in Chrome for iOS

Wed, 01 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Safe Browsing in Chrome for iOS
Weaknesses CWE-284

Wed, 01 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 01 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Remote Navigation Restriction Bypass in Chrome Safe Browsing
Weaknesses CWE-284

Wed, 01 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Remote Navigation Restriction Bypass in Chrome Safe Browsing
Weaknesses CWE-284

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Safe Browsing in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T17:25:51.468Z

Reserved: 2026-06-29T23:03:48.546Z

Link: CVE-2026-13904

cve-icon Vulnrichment

Updated: 2026-07-01T17:10:04.757Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T11:00:15Z

Weaknesses
  • CWE-693

    Protection Mechanism Failure