Junglewise Threat Intelligence

CVE-2026-17994: Google Chrome for Android navigation restriction bypass in Media

CVE-2026-17994 · Severity: info · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A security vulnerability exists in the Google Chrome browser for Android. This flaw could allow a malicious website to bypass standard navigation restrictions, potentially leading to unauthorized redirects or interactions within the browser. While rated as low severity, it represents a failure in the browser's security boundaries when handling media content.

Technical details

An inappropriate implementation vulnerability exists within the Media component of Google Chrome for Android. A remote attacker can exploit this by enticing a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to bypass navigation restrictions, which are intended to control how and where the browser navigates during a session. The vulnerability is addressed in version 151.0.7922.72. The issue is categorized by Chromium as 'Low' severity.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in version 151.0.7922.72
  • 2026-07-30: disclosed

References

Related threats