Junglewise Threat Intelligence

CVE-2026-17821: Google Chrome navigation restriction bypass in Extensions

CVE-2026-17821 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in Google Chrome's extension system, which is used to add features and functionality to the web browser. If a user is tricked into installing a malicious extension, the attacker can bypass built-in navigation restrictions. This could allow the extension to access web content or perform actions that should normally be blocked by the browser's security policies.

Technical details

A vulnerability classified as insufficient policy enforcement exists within the Extensions component of Google Chrome. The flaw allows a specially crafted Chrome Extension to bypass navigation restrictions that are intended to isolate or restrict web traffic. To exploit this, an attacker must successfully use social engineering to convince a user to install a malicious extension. Once installed, the extension can circumvent security policies governing how the browser navigates between different web origins or internal pages. This issue is resolved in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats