Description
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An insecure implementation of Chrome DevTools creates an opportunity for a remote attacker, using a crafted HTML page, to circumvent the browser’s same‑origin policy. The flaw stems from improper handling of certain DevTools features, enabling cross‑origin data access and potential unauthorized information disclosure or session hijacking.

Affected Systems

The vulnerability affects all Google Chrome installations running versions prior to 151.0.7922.72. Users of the stable channel before this build are at risk.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate severity, while the EPSS score of less than 1% shows that malicious exploitation is unlikely at this time. The vulnerability is not currently listed in the CISA KEV catalog, and there is no known widespread exploitation. Attackers would need to host a specially crafted webpage and convince users to open it or exploit a yet‑unknown browsing flaw that triggers the DevTools path. Even though the exploitation window is narrow, the impact of a successful bypass—access to third‑party content, cookie theft, or bypassing content‑security restrictions—makes the risk noteworthy for high‑value assets.

Generated by OpenCVE AI on August 4, 2026 at 12:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.72 or newer to receive the official fix.
  • Disable the DevTools feature globally via the enterprise policy "DeveloperToolsDisabled" to reduce the attack surface until the edition is updated.
  • If an update is not immediately possible, enforce site‑level CSP directives that restrict same‑origin script access and monitor for anomalous dev‑tools usage patterns.

Generated by OpenCVE AI on August 4, 2026 at 12:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Mon, 03 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in DevTools
Weaknesses CWE-346
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Thu, 30 Jul 2026 04:00:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass same origin policy via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-08-03T16:10:58.009Z

Reserved: 2026-07-27T23:34:45.773Z

Link: CVE-2026-17787

cve-icon Vulnrichment

Updated: 2026-08-03T15:58:37.459Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:42.057

Modified: 2026-08-04T14:28:29.290

Link: CVE-2026-17787

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:21Z

Links: CVE-2026-17787 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:15:03Z

Weaknesses