Inappropriate Implementation in Google Chrome Leading to Navigation Bypass
CVE-2026-8009

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
6 May 2026

What is CVE-2026-8009?

A flaw in Google Chrome prior to version 148.0.7778.96 enables a remote attacker to bypass navigation restrictions through a carefully crafted HTML page. This issue arises from an inappropriate implementation in the Cast feature, allowing a compromised renderer process to initiate unauthorized navigation actions, posing potential security risks to users.

Affected Version(s)

Chrome 148.0.7778.96

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.