Description
Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability stems from an inappropriate implementation in Google Chrome’s Isolated Web Apps, allowing a remote attacker to bypass navigation restrictions through a specially crafted HTML page. The issue provides a means for an attacker to force the browser to navigate to arbitrary destinations, potentially leading to phishing, credential theft, or access to internal content that would normally be protected by navigation controls. The weakness can be classified as an instance of improper access control.

Affected Systems

All users of Google Chrome versions prior to 151.0.7922.72 are affected. The vulnerability is relevant to the stable channel of Chrome, impacting both desktop and potentially other platforms where the unsupported version is installed.

Risk and Exploitability

The CVSS severity is listed as Medium and the EPSS score is below 1%, indicating a low estimated probability of exploitation at this time. The vulnerability is not currently listed in the CISA KEV catalog. Exploitation requires a victim to load a crafted HTML page, after which the attacker can force navigation to arbitrary URLs. Because the attack vector involves directing the victim’s browser via a locally crafted page, it is most effective against users who open untrusted web content or click on malicious links.

Generated by OpenCVE AI on August 3, 2026 at 12:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the latest Chrome update (151.0.7922.72 or newer) to remove the flawed navigation logic.
  • Configure Chrome to enable automatic updates or regularly check the official Chrome release channel for new patches.
  • If isolated web apps are required, apply enterprise policies to restrict navigation or disable isolated web apps entirely until a fix is available.

Generated by OpenCVE AI on August 3, 2026 at 12:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sun, 02 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass in Chrome Isolated Web Apps chromium-browser: chromium-browser: Inappropriate implementation in Isolated Web Apps
Weaknesses CWE-425
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 31 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Title Navigation Restriction Bypass in Chrome Isolated Web Apps
Weaknesses CWE-285

Fri, 31 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in Isolated Web Apps in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T17:51:39.026Z

Reserved: 2026-07-27T23:34:44.078Z

Link: CVE-2026-17780

cve-icon Vulnrichment

Updated: 2026-07-31T17:51:31.831Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:41.307

Modified: 2026-08-04T14:29:59.403

Link: CVE-2026-17780

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:19Z

Links: CVE-2026-17780 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T12:15:03Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-425

    Direct Request ('Forced Browsing')