
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-11025 is a Content Security Policy (CSP) bypass vulnerability caused by insufficient policy enforcement in the Navigation component of Google Chrome on Android. It affects all Chrome for Android versions prior to 149.0.7827.53 and allows a remote, unauthenticated attacker to bypass CSP protections via a crafted HTML page, requiring only user interaction (e.g., visiting a malicious site). The vulnerability was reported internally by Google on 2026-03-30 and patched with the Chrome 149 stable channel release on June 2, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, Feedly).
The root cause is classified as CWE-602 (Client-Side Enforcement of Server-Side Security), where Chrome's Navigation subsystem on Android fails to adequately enforce Content Security Policy directives during certain navigation events. This allows a remote attacker to craft a malicious HTML page that triggers a navigation flow in which CSP restrictions are not properly applied, enabling the loading of restricted resources or execution of scripts that should have been blocked. The vulnerability is network-delivered and requires user interaction — specifically, a victim visiting or being redirected to an attacker-controlled page. The Chromium issue tracker entry is #497595264, though full technical details remain restricted pending broad user update (Chrome Releases).
Successful exploitation allows an attacker to bypass Content Security Policy protections on affected Android devices running Chrome, enabling the loading of unauthorized scripts or restricted external resources that CSP is designed to block. The primary impact is on integrity (CVSS integrity impact: High), as an attacker could inject or execute unintended scripts within the context of a web page, potentially facilitating cross-site scripting attacks, data theft, or further exploitation of web application logic. Confidentiality and availability are not directly impacted by this vulnerability alone, but CSP bypass can serve as a stepping stone for more severe attacks (Feedly).
Update Google Chrome on Android to version 149.0.7827.53 or later, which contains the fix for this vulnerability. Enterprise administrators should ensure Chrome is updated via managed device policies (e.g., Google Mobile Management or MDM solutions). As a temporary measure, organizations can monitor for CSP violations using the report-uri or report-to CSP directives to detect potential bypass attempts. No configuration-based workaround is available that fully mitigates the vulnerability without patching (Chrome Releases).
The vulnerability was part of a large Chrome 149 security release that addressed 429 security fixes, drawing general attention from the security community. Security tracking platforms including Tenable (Nessus plugins 319634 and 320419) and Qualys (detection ID 387565) added detection coverage shortly after disclosure. Coverage was noted in security news outlets including security-next.com and pro-linux.de, as well as community discussion on Mastodon (infosec.exchange). No significant individual researcher commentary or vendor statements beyond the standard Google Chrome release advisory have been identified for this specific CVE (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."