Google Chrome PDF Insufficient Policy Enforcement Navigation Restriction Bypass Vulnerability on Android

Vulnerability

A vulnerability in Google Chrome on Android, prior to version 146.0.7680.71, allowed remote attackers to bypass navigation restrictions in PDF files in the Chrome app. This was achieved through a crafted HTML page, exploiting insufficient policy enforcement.

Impact

Exploitation of this vulnerability could lead to unauthorized navigation actions being performed, potentially allowing attackers to manipulate the user's PDF viewing experience or extract information in an unintended manner.

Remediation

Users can update to Google Chrome version 146.0.7680.71 or later to address this vulnerability.

Added: Mar 11, 2026, 10:26 PM
Updated: Mar 11, 2026, 10:26 PM

Vulnerability Rating

Custom Algorithm
spread
8.4
impact
0.6
exploitability
3.8
remediation
7.7
relevance
3.8
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.