Junglewise Threat Intelligence

CVE-2026-17936: Google Chrome navigation restriction bypass in DevTools

CVE-2026-17936 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security issue in Google Chrome's developer tools (DevTools) could allow a malicious website to bypass standard navigation restrictions. To exploit this, an attacker would need to trick a user into performing specific mouse or keyboard actions on a specially crafted webpage. While the risk is considered low, successful exploitation could lead to unauthorized navigation within the browser.

Technical details

A navigation restriction bypass vulnerability exists in the DevTools component of Google Chrome. The flaw stems from an inappropriate implementation that fails to strictly enforce navigation boundaries when specific user interface gestures are performed. A remote attacker can exploit this by hosting a malicious HTML page and inducing a user to interact with the UI in a specific manner. This bypass could allow the attacker to circumvent security policies governing how the browser transitions between different web locations. The issue is addressed in Google Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable channel update 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats