Executive brief
Google Chrome's developer tools (DevTools) contained a flaw that could allow a local attacker to bypass security restrictions that normally control how the browser navigates between pages. By using a specially crafted HTML page, an attacker could potentially circumvent these navigation policies. This issue is primarily a concern for shared systems where an attacker has local access to the device.
Technical details
A vulnerability exists in the DevTools component of Google Chrome due to insufficient policy enforcement. A local attacker can exploit this by convincing a user to open a specially crafted HTML page, which allows the attacker to bypass established navigation restrictions. The vulnerability is classified as a policy bypass (CWE-285) within the Chromium project. The issue was addressed in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux. Access to specific bug details remains restricted to prevent further exploitation until a majority of users have updated.
Affected products
- Google Chrome prior to 151.0.7922.72
Timeline
- 2026-07-29: patched: Fixed in Chrome Stable Channel Update 151.0.7922.71/.72
- 2026-07-30: disclosed: NVD publication date