Description
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-06-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome for iOS allows a remote attacker to bypass navigation restrictions by serving a specially crafted HTML page; the flaw, classified as CWE‑20, causes the browser to navigate to an arbitrary URL chosen by the attacker, thereby altering the user’s browsing experience without executing code or elevating privileges. The impact is limited to the navigation flow and does not expose data or system resources.

Affected Systems

Users of Google Chrome for iOS with versions released before the most recent update are affected; the flaw exists in all earlier releases and is addressed in subsequent updates, as the description indicates the issue was present prior to a certain newer version but the exact fix version is not provided.

Risk and Exploitability

The CVSS score of 4.3 indicates low severity, and the EPSS score of <1% signals a very low probability of exploitation. The CVE has not been reported in the CISA KEV catalog. Exploitation requires host a malicious HTML page and persuade a user to open it. No public exploits are currently known.

Generated by OpenCVE AI on July 15, 2026 at 10:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome for iOS to the latest available release to patch the validation flaw.
  • Ensure automatic updates are enabled for the Chrome app or regularly reinstall the most recent version from the App Store.
  • Apply browsing protection such as Safe Browsing or content filtering to block malicious HTML pages that could exploit the flaw.
  • If the device is managed by an enterprise, enforce a whitelist of trusted URLs and configure the mobile device to prevent untrusted navigation.

Generated by OpenCVE AI on July 15, 2026 at 10:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4672-1 chromium security update
Debian DSA Debian DSA DSA-6378-1 chromium security update
History

Wed, 15 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Chrome iOS Navigation Restriction Bypass via Crafted HTML

Mon, 13 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Bypass in Chrome for iOS

Sun, 12 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Bypass in Chrome for iOS

Sat, 11 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Bypass in Chrome for iOS

Fri, 10 Jul 2026 04:15:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Enables Navigation Bypass in Chrome for iOS

Wed, 08 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Restriction Bypass via Malformed HTML

Wed, 08 Jul 2026 08:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Navigation Restriction Bypass via Malformed HTML

Tue, 07 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Remote Navigation Bypass via Untrusted Input

Tue, 07 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
Title Chrome for iOS Remote Navigation Bypass via Untrusted Input

Mon, 06 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Chrome iOS Navigation Bypass via Untrusted Input

Mon, 06 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Title Chrome iOS Navigation Bypass via Untrusted Input

Sun, 05 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Improper Input Validation in Chrome for iOS

Sat, 04 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Improper Input Validation in Chrome for iOS

Sat, 04 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Untrusted Input in Chrome for iOS

Fri, 03 Jul 2026 19:45:00 +0000

Type Values Removed Values Added
Title Navigation Bypass via Untrusted Input in Chrome for iOS

Fri, 03 Jul 2026 05:15:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Insufficient Validation in Chrome for iOS

Thu, 02 Jul 2026 17:00:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Insufficient Validation in Chrome for iOS

Thu, 02 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass in Chrome for iOS Due to Input Validation Flaw

Thu, 02 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass in Chrome for iOS Due to Input Validation Flaw

Wed, 01 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Untrusted Input in Chrome for iOS

Wed, 01 Jul 2026 16:00:00 +0000

Type Values Removed Values Added
Title Remote Navigation Bypass via Untrusted Input in Chrome for iOS

Wed, 01 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 01 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input Allows Navigation Restriction Bypass

Wed, 01 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 01 Jul 2026 02:15:00 +0000

Type Values Removed Values Added
Title Insufficient Validation of Untrusted Input Allows Navigation Restriction Bypass

Tue, 30 Jun 2026 23:15:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-01T18:52:31.663Z

Reserved: 2026-06-29T23:11:35.246Z

Link: CVE-2026-14066

cve-icon Vulnrichment

Updated: 2026-07-01T12:56:58.677Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-15T10:45:06Z

Weaknesses
  • CWE-20

    Improper Input Validation