Junglewise Threat Intelligence

CVE-2026-17927: Google Chrome insufficient policy enforcement in DevTools

CVE-2026-17927 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's DevTools could allow a malicious browser extension to access data from other websites. For this to happen, an attacker would first need to trick a user into installing a specifically crafted extension. If successful, the attacker could potentially leak sensitive information that should be protected by the browser's security boundaries.

Technical details

An insufficient policy enforcement vulnerability exists in the DevTools component of Google Chrome. The flaw allows a crafted Chrome Extension to bypass cross-origin data protections. To exploit this, an attacker must successfully use social engineering to convince a user to install a malicious extension. Once installed, the extension can leverage DevTools to leak data across origins, violating the Same-Origin Policy. The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats