Description
Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient validation of untrusted input in Chrome for iOS prior to 151.0.7922.72 permits a remote attacker to bypass navigation restrictions via a crafted HTML page. This flaw allows the attacker to direct the browser to any URL that is normally blocked, potentially compromising the user’s security context and privacy. The weakness is an input validation failure (CWE‑20).

Affected Systems

Google Chrome on iOS versions earlier than 151.0.7922.72 are impacted. All devices running those releases are susceptible until they update to the fixed build.

Risk and Exploitability

The CVSS score of 6.5 indicates moderate severity. The EPSS score is less than 1 %, implying a low likelihood of exploitation, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is a crafted web page delivered to the user, possibly from a malicious site. Attackers could target users through phishing or compromised sites, but widespread, automated exploitation is currently unlikely.

Generated by OpenCVE AI on August 2, 2026 at 06:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome on iOS to version 151.0.7922.72 or later as soon as possible
  • Enable Google Safe Browsing to reduce exposure to malicious content
  • Maintain ongoing monitoring of Chrome security advisories for any additional updates or related vulnerabilities

Generated by OpenCVE AI on August 2, 2026 at 06:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sun, 02 Aug 2026 07:00:00 +0000

Type Values Removed Values Added
Title Insufficient Input Validation Bypasses Navigation Restrictions in Chrome for iOS

Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T13:56:48.384Z

Reserved: 2026-07-27T23:34:55.759Z

Link: CVE-2026-17814

cve-icon Vulnrichment

Updated: 2026-07-31T13:56:43.414Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:44.937

Modified: 2026-08-03T17:52:12.013

Link: CVE-2026-17814

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:45:03Z

Weaknesses
  • CWE-20

    Improper Input Validation