Junglewise Threat Intelligence

CVE-2026-17899: Google Chrome privilege escalation in DevTools

CVE-2026-17899 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious browser extension to gain higher-level permissions than intended. To exploit this, an attacker would first need to trick a user into installing a specifically crafted malicious extension. If successful, the attacker could escalate their privileges within the browser environment, potentially accessing data or functions they should not have permission to reach.

Technical details

A privilege escalation vulnerability exists in Google Chrome's DevTools component due to insufficient policy enforcement. The flaw allows a malicious Chrome Extension to bypass intended security boundaries and escalate its privileges. Exploitation requires a user to install a specially crafted extension, making the attack vector local/social engineering-based. Google has addressed this issue in Chrome version 151.0.7922.72. The Chromium project classified this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats