Executive brief
A vulnerability in Google Chrome's DevTools component could allow a remote attacker to bypass navigation restrictions. By convincing a user to visit a specially crafted website, an attacker could potentially force the browser to navigate to unintended locations. This issue primarily affects the security boundaries within the browser's developer tools.
Technical details
This vulnerability is classified as insufficient validation of untrusted input within the DevTools component of Google Chrome. A remote attacker can exploit this by hosting a crafted HTML page that, when processed by the browser, bypasses intended navigation restrictions. The attack vector is network-based and requires the victim to navigate to the attacker-controlled content. This flaw was addressed in Chrome version 151.0.7922.72. Chromium has assigned this a security severity of Low.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in version 151.0.7922.72
- 2026-07-30: disclosed: NVD publication date