Description
Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from missing policy enforcement for navigation in Google Chrome’s Actor component, which allowed a remote attacker to deliver a crafted HTML page that bypasses normal navigation restrictions. This weakness is classified as CWE‑602, pointing to an inadequate control over navigation actions. The technical effect is that the browser can be forced to navigate to a URL that would normally be blocked, potentially enabling phishing or other malicious redirection.

Affected Systems

All users running Google Chrome whose version is below 150.0.7871.47 on any supported operating system are affected by this issue.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity. The EPSS score is reported as less than 1%, and the vulnerability is not listed in the CISA KEV catalog, suggesting a comparatively low likelihood of exploitation. Based on the description, the attacker must present the victim with the malicious HTML page, implying that user interaction or a compromised site is required. While the flaw does not give code execution, it enables unauthorized navigation, which could be leveraged for phishing or other social engineering attacks.

Generated by OpenCVE AI on July 17, 2026 at 02:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version.7871.47 or later via the built‑in update mechanism.
  • If automatic updates are disabled, re‑enable them or perform a manual update by downloading the latest installer from Google’s official website.
  • Until the update is applied, consider using a browser extension that blocks unauthorized redirects or enforcing stricter web browsing policies as a provisional countermeasure.

Generated by OpenCVE AI on July 17, 2026 at 02:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 17 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Insufficient Policy Enforcement in Chrome Actor

Tue, 14 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Mon, 13 Jul 2026 05:30:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Allows Unauthorized Navigation via Crafted HTML in Google Chrome

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insufficient Policy Enforcement Allows Unauthorized Navigation via Crafted HTML in Google Chrome

Thu, 09 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Google Chrome Actor

Tue, 07 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Crafted HTML in Google Chrome Actor

Mon, 06 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Mon, 06 Jul 2026 03:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Crafted HTML in Chrome Actor

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Insufficient Policy Enforcement in Chrome Actor Component

Sat, 04 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Unauthorized Navigation via Insufficient Policy Enforcement in Chrome Actor Component

Sat, 04 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome Actor Navigation Policy Bypass via Crafted HTML

Fri, 03 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Chrome Actor Navigation Policy Bypass via Crafted HTML

Fri, 03 Jul 2026 02:45:00 +0000

Type Values Removed Values Added
Title Navigation Policy Bypass via Crafted HTML in Google Chrome

Thu, 02 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Navigation Policy Bypass via Crafted HTML in Google Chrome

Thu, 02 Jul 2026 04:45:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass via Crafted HTML
Weaknesses CWE-285

Wed, 01 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Policy Bypass via Crafted HTML
Weaknesses CWE-285

Wed, 01 Jul 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Google Chrome
Weaknesses CWE-284
CWE-285

Wed, 01 Jul 2026 01:45:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Crafted HTML in Google Chrome
Weaknesses CWE-284
CWE-285

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Actor in Google Chrome prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T16:06:56.798Z

Reserved: 2026-06-29T23:03:54.875Z

Link: CVE-2026-13930

cve-icon Vulnrichment

Updated: 2026-07-01T15:17:06.096Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T02:30:08Z

Weaknesses
  • CWE-602

    Client-Side Enforcement of Server-Side Security