Description
Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient policy enforcement in the Actor component of Google Chrome, allowing a remote attacker to serve a crafted HTML page that forces the browser to navigate to a URL normally blocked by navigation restrictions. The flaw is classified as CWE‑602, indicating a failure to enforce proper bounds on information flow between components. This can lead to unauthorized navigation and potentially expose users to phishing sites or malicious content.

Affected Systems

All users running Google Chrome versions earlier than 150.0.7871.47 on any supported operating system are affected by this issue.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% and the absence from the CISA KEV catalog suggest a relatively low likelihood of widespread exploitation. Exploitation requires the attacker to deliver the crafted HTML page to the victim, typically via user interaction or a compromised site; it does not provide code execution, but it enables malicious redirection that can be used for phishing or social engineering.

Generated by OpenCVE AI on July 31, 2026 at 16:16 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or later using the built‑in update mechanism.
  • If automatic updates are disabled, enable them or manually download and install the latest Chrome installer from Google’s official website.
  • Until the update is applied, consider using a browser extension or policy that blocks unauthorized redirects as a temporary countermeasure.

Generated by OpenCVE AI on July 31, 2026 at 16:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Remote Redirect via Crafted HTML Due to Insufficient Navigation Policy in Google Chrome

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Remote Redirect via Crafted HTML Due to Insufficient Navigation Policy in Google Chrome

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Insufficient Policy Enforcement in Chrome Actor

Fri, 17 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Insufficient Policy Enforcement in Chrome Actor

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Allows Unauthorized Navigation via Crafted HTML in Google Chrome

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Allows Unauthorized Navigation via Crafted HTML in Google Chrome

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Google Chrome Actor

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Google Chrome Actor

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Insufficient Policy Enforcement in Chrome Actor Component

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Insufficient Policy Enforcement in Chrome Actor Component

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Actor Navigation Policy Bypass via Crafted HTML

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Actor Navigation Policy Bypass via Crafted HTML

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Navigation Policy Bypass via Crafted HTML in Google Chrome

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Navigation Policy Bypass via Crafted HTML in Google Chrome

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass via Crafted HTML
Weaknesses CWE-285

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass via Crafted HTML
Weaknesses CWE-285

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Google Chrome
Weaknesses CWE-284
CWE-285

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Google Chrome
Weaknesses CWE-284
CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:56.798Z

Reserved: 2026-06-29T23:03:54.875Z

Link: CVE-2026-13930

cve-icon Vulnrichment

Updated: 2026-07-01T15:17:06.096Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:30:17Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security