Low chrome Logic Error 🔧 Commit mapped

Overview

Low
Severity
CVSS
No
Exploited ITW
Fixed
Fix Status
ImpactInsufficient validation of untrusted input in Navigation
DescriptionInsufficient validation of untrusted input in Navigation
ComponentNavigation
Bug ClassLogic Error
Tracker513503197
Fix commit0429536715e4 (chromium/src) +14/-1
CISA KEVNot listed
CreditedGoogle
Disclosed2026-07-29

Files Changed

  • content/browser/renderer_host/navigation_controller_impl.cc
From 0429536715e40b2ddb3ed7bb39bb14869b00515a Mon Sep 17 00:00:00 2001
From: Yao Xiao <[email protected]>
Date: Thu, 04 Jun 2026 11:47:58 -0700
Subject: [PATCH] Fix cross-origin history manipulation via forged document sequence number

This CL updates `SetSkippableForSameDocumentEntries` to ensure the
skippable bit is only propagated to history entries that share the same
SiteInstance as the reference entry.

Rationale:
Previously, the browser relied solely on the renderer-provided document
sequence number to identify related entries. This allowed a compromised
renderer to forge a document sequence number matching a cross-origin
entry, tricking the browser into marking a victim site's history entry
as skippable (and potentially pruning it). Enforcing a SiteInstance
check prevents this vulnerability.

Bug: 513503197
Change-Id: I9bec978e221382eab485c689cd7e83721d9083bb
Reviewed-on: https://chromium-review.googlesource.com/c/chromium/src/+/7896997
Reviewed-by: Charlie Reis <[email protected]>
Commit-Queue: Yao Xiao <[email protected]>
Cr-Commit-Position: refs/heads/main@{#1641833}
---

diff --git a/content/browser/renderer_host/navigation_controller_impl.cc b/content/browser/renderer_host/navigation_controller_impl.cc
index 7fbd813d..1260b2f6 100644
--- a/content/browser/renderer_host/navigation_controller_impl.cc
+++ b/content/browser/renderer_host/navigation_controller_impl.cc
@@ -5197,8 +5197,21 @@
       reference_entry->root_node()->frame_entry->document_sequence_number();
   for (int index = 0; index < GetEntryCount(); index++) {
     auto* entry = GetEntryAtIndex(index);
+
+    // A compromised renderer could forge a document sequence number (DSN) to
+    // match a cross-origin entry, attempting to mark a victim site's history
+    // entry as skippable. Enforcing a SiteInstance check prevents this.
+    //
+    // Note: When restoring a tab, NavigationEntries do not get SiteInstances
+    // until they are visited again. We allow the check to pass if `entry`'s
+    // SiteInstance is null to ensure same-document entries are correctly
+    // marked skippable after a restore. The risk is acceptable because an
+    // attacker cannot trigger a tab restore, DSNs are difficult to guess
+    // across sessions, and the impact is minimal.
     if (entry->root_node()->frame_entry->document_sequence_number() ==
-        document_sequence_number) {
+            document_sequence_number &&
+        (!entry->site_instance() ||
+         entry->site_instance() == reference_entry->site_instance())) {
       entry->set_should_skip_on_back_forward_ui(skippable);
     }
   }
Loading diff…

Original Bug Report

The reporter's bug is still restricted on the tracker. Chrome de-restricts security bugs ~30–90 days after the fix ships; a later run will backfill it here.