Junglewise Threat Intelligence

CVE-2026-18014: Google Chrome improper input validation in DevTools

CVE-2026-18014 · Severity: info · CVSS 0 · Published 2026-07-30

Technologies: Google Chrome. Vendors: Google.

Executive brief

A vulnerability was identified in Google Chrome's DevTools, a set of web developer tools built directly into the browser. A remote attacker could use a specially crafted file to bypass security restrictions that normally control how the browser navigates between pages. While rated as low severity, this could potentially allow for unauthorized navigation or interactions within the browser environment.

Technical details

An improper input validation vulnerability (CWE-20) exists in the DevTools component of Google Chrome. The flaw stems from insufficient validation of untrusted input, which can be exploited by a remote attacker using a malicious file to bypass navigation restrictions. This could allow an attacker to force the browser to navigate to unintended locations or bypass security boundaries enforced by the DevTools interface. The vulnerability is addressed in Google Chrome version 151.0.7922.72 for Windows and Mac, and 151.0.7922.71 for Linux.

Affected products

  • Google Chrome prior to 151.0.7922.72

Timeline

  • 2026-07-29: patched: Fixed in Chrome version 151.0.7922.72
  • 2026-07-30: disclosed: NVD publication date

References

Related threats