Junglewise Threat Intelligence

CVE-2026-17976: Google Chrome access control bypass in Extensions

CVE-2026-17976 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser that supports third-party extensions to add functionality. A security flaw in the way Chrome handles extension policies could allow a malicious extension to bypass security restrictions. If a user is tricked into installing a specially crafted extension, the attacker could gain unauthorized access to data or perform actions on websites that should have been restricted.

Technical details

A vulnerability exists in the Extensions component of Google Chrome due to insufficient policy enforcement. The flaw allows a malicious extension to bypass discretionary access control (DAC) mechanisms by utilizing a specially crafted domain name. To exploit this, an attacker must first convince a user to install a malicious extension. Once installed, the extension can circumvent intended security boundaries to access restricted resources or data. This issue is addressed in Chrome version 151.0.7922.72.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats