Description
Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the SplitView component of Google Chrome that allows an attacker who has already compromised the renderer process to manipulate navigation rules through a specifically crafted HTML page. This flaw, classified as a privilege escalation (CWE‑284), lets the compromised renderer ignore navigation restrictions that the browser would normally enforce, potentially allowing the user to be redirected to unintended sites.

Affected Systems

Google Chrome installations running any versions prior to 150.0.7871.47 are susceptible, regardless of the operating system. The flaw resides in the renderer, so any Chrome instance deploying that code is at risk until the software is updated to the patched release or newer.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to initially compromise the renderer process; once that condition is met, a malicious HTML page can deactivate navigation restrictions, thereby bypassing the browser's intended controls.

Generated by OpenCVE AI on July 15, 2026 at 10:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Google Chrome version 150.0.7871.47 or newer to eliminate the SplitView weakness.
  • Refer to Chrome’s official update mechanisms or security advisories for patch management and apply new releases promptly.
  • Maintain a consistent update schedule by checking for new Chrome releases on a regular basis to ensure timely application of security fixes.

Generated by OpenCVE AI on July 15, 2026 at 10:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass

Sun, 12 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass

Sat, 11 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass

Wed, 08 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via SplitView in Chrome

Tue, 07 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via SplitView in Chrome

Mon, 06 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass After Renderer Compromise

Sun, 05 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass After Renderer Compromise

Sat, 04 Jul 2026 23:30:00 +0000

Type Values Removed Values Added
Title SplitView Navigation Restriction Bypass in Chrome

Sat, 04 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title SplitView Navigation Restriction Bypass in Chrome

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass via Renderer Compromise
Weaknesses CWE-269
CWE-601

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Bypass via Renderer Compromise
Weaknesses CWE-269
CWE-601

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass via Compromised Renderer
Weaknesses CWE-269
CWE-601

Wed, 01 Jul 2026 03:00:00 +0000

Type Values Removed Values Added
Title Chrome SplitView Navigation Restriction Bypass via Compromised Renderer
Weaknesses CWE-269
CWE-601

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in SplitView in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T14:08:31.718Z

Reserved: 2026-06-29T23:04:00.454Z

Link: CVE-2026-13953

cve-icon Vulnrichment

Updated: 2026-07-02T14:08:26.792Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T11:00:14Z

Weaknesses