Junglewise Threat Intelligence

CVE-2026-17929: Google Chrome navigation bypass in DevTools

CVE-2026-17929 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's developer tools (DevTools) contained a security flaw that could allow a malicious file to bypass standard navigation restrictions. This component is typically used by developers to inspect and debug web pages. If exploited, an attacker could potentially force the browser to navigate to unauthorized locations or bypass security boundaries using a specially crafted file.

Technical details

A vulnerability exists in Google Chrome's DevTools component due to insufficient validation of untrusted input. A remote attacker could exploit this by providing a malicious file that, when processed by DevTools, allows for a bypass of navigation restrictions. This is classified as improper input validation (CWE-20). The issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. The Chromium project assigned this a 'Low' severity rating.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: disclosed: Date of Chrome Stable Channel Update announcement.
  • 2026-07-29: advisory: NVD publication date.

References

Related threats