Junglewise Threat Intelligence

CVE-2026-17974: Google Chrome navigation restriction bypass in DevTools

CVE-2026-17974 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome's developer tools (DevTools) contained a flaw that could allow a local attacker to bypass security restrictions that normally control how the browser navigates between pages. By using a specially crafted HTML page, an attacker could potentially circumvent these navigation policies. This issue is primarily a concern for shared systems where an attacker has local access to the device.

Technical details

A vulnerability exists in the DevTools component of Google Chrome due to insufficient policy enforcement. A local attacker can exploit this by convincing a user to open a specially crafted HTML page, which allows the attacker to bypass established navigation restrictions. The vulnerability is classified as a policy bypass (CWE-285) within the Chromium project. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats