Description
Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)
Published: 2026-06-30
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An integer overflow exists in Google Chrome’s Safe Browsing module on macOS. The flaw allows a remote attacker to craft a malicious file that, when opened by the browser, triggers the overflow and causes Safe Browsing to incorrectly treat the file as safe. This misclassification enables navigation to URLs that would normally be blocked, effectively bypassing the browser’s protection. The vulnerability is classified as CWE‑472 and does not provide arbitrary code execution.

Affected Systems

macOS users running Google Chrome versions earlier than 150.0.7871.47 are affected. Devices upgraded to 150.0.7871.47 or later enjoy the fix.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity, but the EPSS score of less than 1% and absence from the CISA KEV catalog suggest a low likelihood of current exploitation. Based on the description, an attacker must supply a malicious file—typically delivered via email, download, or file sharing—that is opened by the browser. Once processed, the attacker can navigate to otherwise blocked URLs. The flaw does not grant arbitrary code execution or system compromise, but it undermines the browser’s security controls.

Generated by OpenCVE AI on July 16, 2026 at 12:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 150.0.7871.47 or newer on all macOS devices
  • If immediate upgrade is not feasible, configure Chrome policies to enforce stricter Safe Browsing checks or block navigation to unsafe URLs
  • As a temporary workaround, disable the Safe Browsing feature until the patch can be applied
  • Maintain constant vendor update monitoring and apply any future revisions promptly

Generated by OpenCVE AI on July 16, 2026 at 12:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Thu, 16 Jul 2026 12:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Bypass

Tue, 14 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Bypass

Thu, 09 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Integer Overflow Allows Navigation Bypass on macOS Chrome

Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Title Safe Browsing Integer Overflow Allows Navigation Bypass on macOS Chrome

Tue, 07 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome's Safe Browsing on macOS Enables Remote Navigation Bypass

Mon, 06 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome's Safe Browsing on macOS Enables Remote Navigation Bypass

Sun, 05 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome Safe Browsing allows navigation restriction bypass on macOS

Sat, 04 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Title Integer overflow in Chrome Safe Browsing allows navigation restriction bypass on macOS

Sat, 04 Jul 2026 00:00:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass via Integer Overflow in macOS Chrome

Fri, 03 Jul 2026 16:45:00 +0000

Type Values Removed Values Added
Title Safe Browsing Navigation Restriction Bypass via Integer Overflow in macOS Chrome

Fri, 03 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Restriction Bypass on macOS

Thu, 02 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190

Thu, 02 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-190
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Restriction Bypass on macOS

Wed, 01 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Restriction Bypass on Mac

Wed, 01 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 05:45:00 +0000

Type Values Removed Values Added
Title Integer Overflow in Chrome Safe Browsing Allows Navigation Restriction Bypass on Mac

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Integer overflow in Safe Browsing in Google Chrome on Mac prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a malicious file. (Chromium security severity: Medium)
Weaknesses CWE-472
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-02T17:04:54.645Z

Reserved: 2026-06-29T23:04:05.753Z

Link: CVE-2026-13974

cve-icon Vulnrichment

Updated: 2026-07-02T14:23:37.563Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-16T12:30:03Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter