Junglewise Threat Intelligence

CVE-2026-17890: Google Chrome improper input validation in DevTools

CVE-2026-17890 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability exists in Google Chrome's DevTools, a set of web developer tools built directly into the browser. If an attacker has already partially compromised the browser's rendering process, they could use this flaw to break out of the security sandbox that normally isolates web pages from the rest of the computer. This could allow the attacker to gain broader access to the underlying operating system and user data.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw allows a remote attacker to perform a sandbox escape, provided they have already achieved code execution within a compromised renderer process. By enticing a user to visit a specially crafted HTML page, the attacker can leverage the insufficient validation in DevTools to bypass the browser's security boundaries. This vulnerability was addressed in Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats