Description
Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An implementation flaw in Chrome for iOS allows a remote attacker to bypass the browser’s navigation restrictions by serving a specially crafted HTML page. When such a page is loaded, the built‑in navigation guard is circumvented, enabling the browser to follow arbitrary URLs that would normally be blocked. The vulnerability is identified as CWE‑284, Improper Access Control, and can be exploited to silently redirect users to malicious sites or load unauthorized content. The impact is limited to navigation control, but it can be leveraged in targeted phishing or social engineering campaigns.

Affected Systems

Google Chrome for iOS versions prior to 151.0.7922.72 are affected. Any device running an older build of Chrome on iOS, regardless of the underlying iOS version, is at risk because the flaw resides in Chrome’s navigation handling code.

Risk and Exploitability

The CVSS score of 4.3 classifies the issue as low severity, and the EPSS score of less than 1 % indicates a very small probability of exploitation. The flaw is triggered by visiting a crafted page in Chrome on iOS, so the attack vector is remote and requires user interaction. The vulnerability is not listed in CISA’s KEV catalog, suggesting no widespread active exploitation. Nonetheless, a determined attacker could use the bypass to facilitate targeted phishing attacks or to load disallowed content that may lead to further compromise.

Generated by OpenCVE AI on August 2, 2026 at 06:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome for iOS to version 151.0.7922.72 or later, which contains the fix for the navigation restriction bypass.
  • If an upgrade cannot be performed immediately, enforce navigation policies through mobile device management to block unauthorized redirects and mitigate exposure.
  • After applying a patch or policy change, monitor network traffic and browser logs for unexpected redirection behavior and review access controls.

Generated by OpenCVE AI on August 2, 2026 at 06:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sun, 02 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Restriction Bypass via Crafted HTML Page in Chrome for iOS

Fri, 31 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Restriction Bypass via Crafted HTML Page in Chrome for iOS

Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T19:37:57.317Z

Reserved: 2026-07-27T23:37:05.570Z

Link: CVE-2026-17944

cve-icon Vulnrichment

Updated: 2026-07-30T19:37:53.311Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:58.693

Modified: 2026-08-03T15:05:21.507

Link: CVE-2026-17944

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:15:12Z

Weaknesses