Junglewise Threat Intelligence

CVE-2026-17988: Google Chrome improper input validation in Navigation

CVE-2026-17988 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's navigation component could allow a remote attacker to bypass security restrictions. This could potentially lead to unauthorized access to data or the ability to perform actions on behalf of the user if the attacker has already compromised part of the browser's internal processes.

Technical details

An improper input validation vulnerability (CWE-20) exists in the Navigation component of Google Chrome. The flaw allows a remote attacker to bypass navigation restrictions by utilizing a specially crafted HTML page. A precondition for this attack is that the attacker must have already compromised the renderer process. By exploiting this vulnerability, the attacker can circumvent security boundaries intended to restrict browser navigation. The issue is resolved in Google Chrome version 151.0.7922.72 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: advisory: Google released the stable channel update fixing the issue.
  • 2026-07-30: disclosed: CVE published in the NVD dataset.

References

Related threats