Junglewise Threat Intelligence

CVE-2026-17853: Google Chrome script injection in DevTools

CVE-2026-17853 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's DevTools, a set of web developer tools built directly into the browser, contained a vulnerability that could allow an attacker to inject malicious scripts or HTML into privileged browser pages. This issue requires the attacker to have already compromised the browser's rendering process, typically through a separate exploit. If successful, the attacker could gain unauthorized access to sensitive browser functions or data by manipulating internal pages that usually have higher security permissions than standard websites.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the DevTools component of Google Chrome. The flaw allows a remote attacker to perform script or HTML injection into privileged browser pages. A significant precondition for this attack is that the adversary must have already achieved code execution within a compromised renderer process. By utilizing a specially crafted HTML page, the attacker can bypass security boundaries to interact with internal, high-privilege browser interfaces. This vulnerability is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats