Junglewise Threat Intelligence

CVE-2026-17756: Google Chrome navigation restriction bypass in Presentation

CVE-2026-17756 · Severity: info · CVSS 6.5 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability has been identified in Google Chrome's Presentation feature, which allows the browser to display content on external screens or projectors. An attacker could use a specially crafted website to bypass security restrictions that normally control how the browser navigates between pages. This could lead to unauthorized navigation or the loading of content that should otherwise be restricted by the browser's security policies.

Technical details

A vulnerability classified as insufficient policy enforcement exists in the Presentation API component of Google Chrome. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a maliciously crafted HTML page. This bypass occurs because the browser fails to strictly enforce security policies during presentation-related navigation events. The vulnerability was addressed in Chrome version 151.0.7922.72 for Windows, Mac, and Linux. While the NVD entry lists the severity as 'info', the Chromium project internally rated this as 'Medium' severity.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats