Executive brief
A vulnerability in Google Chrome's developer tools (DevTools) could allow a malicious website to bypass security restrictions that normally prevent unauthorized navigation. To exploit this, an attacker must trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. While the risk is considered low, successful exploitation could lead to unexpected browser behavior or navigation to restricted content.
Technical details
An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be leveraged by a remote attacker to bypass navigation restrictions. Exploitation requires a precondition where the victim is lured to a malicious HTML page and convinced to perform specific UI gestures. This bypass could allow the attacker to trigger navigations that should otherwise be restricted by the browser's security policies. The issue is addressed in Chrome version 151.0.7922.72.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.72
- 2026-07-30: disclosed: CVE published to NVD