Description
Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability lies in insufficient validation of untrusted input within the PageInfo component of Google Chrome. A remote attacker who has already compromised the renderer process can deliver a crafted HTML page that bypasses browser‑enforced navigation restrictions. The flaw does not allow direct remote code execution; when a renderer is already under attacker control.

Affected Systems

All releases of Google Chrome prior to 150.0.7871.47 are affected; any user running an older build is susceptible, while newer releases include the required input validation fix.

Risk and Exploitability

The EPSS score of less than 1 % indicates a very low probability of exploitation, and the CVSS score of 6.5 reflects medium severity. The flaw is not listed in the CISA KEV catalog. Exploitation requires the attacker to first gain control of the renderer process, which typically arises from a separate vulnerability or a social‑engineered compromise. The description indicates that no independent attack path exists, so it is inferred that initial renderer compromise is mandatory. The overall likelihood of successful exploitation remains low due to this high barrier to initial compromise.

Generated by OpenCVE AI on July 15, 2026 at 23:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deploy the latest Chrome stable release (≥150.0.7871.47) to address the input validation defect identified by CWE-20.
  • Enable Chrome's site isolation and sandboxing features to limit the impact of any compromised renderer process.
  • Monitor browser activity for unexpected navigation events and block sites that trigger navigation bypasses.

Generated by OpenCVE AI on July 15, 2026 at 23:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass via Untrusted Input in Chrome PageInfo

Tue, 14 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in PageInfo Enables Navigation Bypass

Mon, 13 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in PageInfo Enables Navigation Bypass

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Enables Navigation Bypass

Thu, 09 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Enables Navigation Bypass

Wed, 08 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Chrome PageInfo Input Validation Flaw Enables Navigation Restriction Bypass

Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Chrome PageInfo Input Validation Flaw Enables Navigation Restriction Bypass

Mon, 06 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Bypass Navigation Restrictions via Unvalidated PageInfo Input in Chrome

Sun, 05 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Bypass Navigation Restrictions via Unvalidated PageInfo Input in Chrome

Sun, 05 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome PageInfo Enables Navigation Bypass

Sun, 05 Jul 2026 07:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation in Chrome PageInfo Enables Navigation Bypass

Sat, 04 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Bypasses Navigation Restrictions in Compromised Renderer

Sat, 04 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Bypasses Navigation Restrictions in Compromised Renderer

Fri, 03 Jul 2026 23:45:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Failure Enables Navigation Bypass in Chrome

Fri, 03 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Untrusted Input Validation Failure Enables Navigation Bypass in Chrome

Fri, 03 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Chrome Renderer Navigation Bypass via Input Validation Failure

Thu, 02 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Title Chrome Renderer Navigation Bypass via Input Validation Failure

Thu, 02 Jul 2026 04:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Leading to Navigation Bypass

Wed, 01 Jul 2026 22:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation in Chrome PageInfo Leading to Navigation Bypass

Wed, 01 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Restriction Bypass in Chrome

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Restriction Bypass in Chrome

Wed, 01 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Bypass Allowing Navigation Restriction Circumvention

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Renderer Process Input Validation Bypass Allowing Navigation Restriction Circumvention

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in PageInfo in Google Chrome prior to 150.0.7871.47 allowed a remote attacker who had compromised the renderer process to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:52:40.954Z

Reserved: 2026-06-29T23:11:35.066Z

Link: CVE-2026-14065

cve-icon Vulnrichment

Updated: 2026-07-01T12:58:15.500Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T23:30:04Z

Weaknesses
  • CWE-20

    Improper Input Validation