Junglewise Threat Intelligence

CVE-2026-17921: Google Chrome improper input validation in Navigation

CVE-2026-17921 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome, a widely used web browser, contained a security flaw in its navigation component. This vulnerability could allow an attacker who has already partially compromised the browser's rendering engine to bypass security restrictions that normally control how the browser moves between different websites. In practice, this could be used to facilitate further attacks or access restricted content by tricking the browser into navigating to unauthorized locations.

Technical details

An improper input validation vulnerability (CWE-20) existed in the Navigation component of Google Chrome. A remote attacker who had already achieved code execution within a compromised renderer process could exploit this flaw by serving a specially crafted HTML page. This allowed the attacker to bypass established navigation restrictions, potentially leading to further sandbox escapes or unauthorized cross-origin interactions. The issue is resolved in Google Chrome version 151.0.7922.72 and later.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Stable channel update released for Windows, Mac, and Linux.
  • 2026-07-30: disclosed: NVD publication date.

References

Related threats