Junglewise Threat Intelligence

CVE-2026-13929: Google Chrome for Android navigation bypass in DevTools

CVE-2026-13929 · Severity: info · CVSS 4.3 · Published 2026-06-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome on Android is a mobile web browser. A security flaw in its developer tools (DevTools) could allow a malicious file on the device to bypass standard navigation restrictions. This could potentially lead to unauthorized access to local files or restricted web content if a user is tricked into opening a specially crafted file.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome for Android. The flaw stems from insufficient policy enforcement when handling navigation requests initiated through developer tools. A local attacker can exploit this by providing a malicious file that, when processed, bypasses intended navigation restrictions. This could allow for unauthorized navigation to restricted origins or local resources. The vulnerability is fixed in version 150.0.7871.47 and later.

Affected products

  • Google Chrome prior to 150.0.7871.47

Timeline

  • 2026-06-30: disclosed
  • 2026-06-30: patched

References

Related threats