Description
Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper SplitView implementation in Google Chrome allows a remote attacker who has already compromised the renderer process to bypass navigation restrictions by serving a crafted HTML page. This is an Access Control Failure (CWE-284) that lets the browser ignore navigation rules normally enforced, potentially redirecting the user to unintended sites or accessing restricted resources. The Chromium security severity is Medium.

Affected Systems

All installations of Google Chrome older than version 150.0.7871.47 are affected. The weakness resides in the SplitView component of the renderer, so any Chrome instance containing the vulnerable code is at risk until updated.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation in the short term. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to first compromise the renderer process; once that condition is satisfied, a malicious HTML page can deactivate the navigation restrictions, thereby bypassing the browser’s intended safeguards.

Generated by OpenCVE AI on July 31, 2026 at 16:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Google Chrome version 150.0.7871.47 or later to remove the SplitView access control flaw.
  • Refer to Chrome’s official update mechanisms or security advisories for patch management and apply new releases promptly.
  • Maintain a consistent update schedule by checking for new Chrome releases on a regular basis to ensure timely application of security fixes.

Generated by OpenCVE AI on July 31, 2026 at 16:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Fri, 31 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Chrome Navigation Restriction Bypass via Renderer Compromise

Sat, 25 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Control Bypass

Wed, 22 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Control Bypass

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via SplitView in Chrome

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via SplitView in Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass After Renderer Compromise

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass After Renderer Compromise

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title SplitView Navigation Restriction Bypass in Chrome

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title SplitView Navigation Restriction Bypass in Chrome

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass via Renderer Compromise
Weaknesses CWE-269
CWE-601

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass via Renderer Compromise
Weaknesses CWE-269
CWE-601

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass via Compromised Renderer
Weaknesses CWE-269
CWE-601

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass via Compromised Renderer
Weaknesses CWE-269
CWE-601

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T14:08:31.718Z

Reserved: 2026-06-29T23:04:00.454Z

Link: CVE-2026-13953

cve-icon Vulnrichment

Updated: 2026-07-02T14:08:26.792Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T16:15:03Z

Weaknesses