Junglewise Threat Intelligence

CVE-2026-17931: Google Chrome navigation restriction bypass in DevTools

CVE-2026-17931 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability in Google Chrome's Developer Tools (DevTools) could allow a malicious website to bypass standard navigation restrictions. DevTools is a set of web developer tools built directly into the browser. If exploited, an attacker could potentially force the browser to navigate to unauthorized locations or bypass security boundaries intended to isolate different websites.

Technical details

An inappropriate implementation vulnerability exists in the DevTools component of Google Chrome. The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. This bypass could potentially lead to unauthorized cross-origin navigations or the circumvention of security policies designed to restrict frame or window movement. The vulnerability is addressed in Google Chrome version 151.0.7922.72. Google classifies this as a Low severity issue.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats