Description
Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Insufficient policy enforcement in Glic, a component of Google Chrome for Android, allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. The flaw does not provide direct code execution; instead it permits an attacker to trick the browser into visiting a malicious site or performing a navigation action that normally would be blocked. This weakness is classified as CWE-602, indicating insufficient policy enforcement. The vulnerability is classified as medium severity by the Chromium security team, reflecting the potential for phishing or unintended navigation but no immediate denial of service or data disclosure.

Affected Systems

Google Chrome on Android versions earlier than 151.0.7922.72 are affected. Users running those builds are vulnerable; the issue is fixed in the stated release 151.0.7922.72 and later.

Risk and Exploitability

The EPSS score is less than 1% and the vulnerability is not currently listed in the CISA KEV catalog, indicating a low overall exploitation probability. The CVSS score of 6.5 indicates medium severity. The likely attack vector is via a user opening a maliciously crafted web page or visiting a site that serves such content; no additional privileges or network access are required. Given the mild exploitation likelihood and the non-destructive impact, the risk is moderate but still actionable.

Generated by OpenCVE AI on August 4, 2026 at 12:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome for Android to version 151.0.7922.72 or later to apply the policy enforcement fix.
  • Ensure that Glic policy enforcement is enabled in the browser settings, if configurable, to prevent navigation bypasses.
  • If an update is not immediately possible, consider using network or web filtering solutions to block known malicious domains or restrict access to untrusted sites until the patch is applied.

Generated by OpenCVE AI on August 4, 2026 at 12:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Sat, 01 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Insufficient policy enforcement in Glic
Weaknesses CWE-1021
References
Metrics threat_severity

None

threat_severity

Moderate


Fri, 31 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-602
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in Glic in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-31T13:58:25.590Z

Reserved: 2026-07-27T23:34:49.874Z

Link: CVE-2026-17805

cve-icon Vulnrichment

Updated: 2026-07-31T13:58:20.404Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:43.950

Modified: 2026-08-03T13:44:31.443

Link: CVE-2026-17805

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-30T00:19:26Z

Links: CVE-2026-17805 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T12:15:03Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-602

    Client-Side Enforcement of Server-Side Security