Description
Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-07-30
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Google Chrome versions prior to 151.0.7922.72, the DevTools implementation contains an inappropriate check that can be exploited to bypass the browser’s navigation restrictions. A remote attacker can craft an HTML page that, when a user performs specific UI gestures, forces Chrome to navigate to an attacker-controlled site, thereby enabling phishing or other malicious activity without granting arbitrary code execution.

Affected Systems

The vulnerability affects Google Chrome, specifically all releases before 151.0.7922.72. Users of these older builds are at risk; no other vendors or products are listed as impacted.

Risk and Exploitability

The CVSS score of 6.5 indicates a moderate risk, while the EPSS score of less than 1% suggests a very low likelihood of real‑world exploitation at present. The vulnerability is not listed in the CISA KEV catalog, implying no confirmed public exploitation. Successful exploitation requires user interaction with a crafted page and specific gestures, which raises the barrier but does not eliminate the risk.

Generated by OpenCVE AI on August 2, 2026 at 06:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 151.0.7922.72 or later to address the vulnerable DevTools implementation.
  • Ensure that the browser is updated from the official stable channel so that future security fixes are automatically applied.
  • If an update cannot be applied immediately, configure a group policy or similar administrative control to disable or restrict DevTools access for untrusted web content, thereby reducing the attack surface.

Generated by OpenCVE AI on August 2, 2026 at 06:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DLA Debian DLA DLA-4710-1 chromium security update
Debian DSA Debian DSA DSA-6408-1 chromium security update
History

Fri, 31 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
Title chromium-browser: chromium-browser: Inappropriate implementation in DevTools
Weaknesses CWE-1021
References
Metrics threat_severity

None

threat_severity

Low


Thu, 30 Jul 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
CWE-693
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 30 Jul 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Thu, 30 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-07-30T18:58:33.925Z

Reserved: 2026-07-27T23:37:03.966Z

Link: CVE-2026-17936

cve-icon Vulnrichment

Updated: 2026-07-30T18:58:30.637Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-30T01:16:57.860

Modified: 2026-08-03T17:28:31.407

Link: CVE-2026-17936

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-30T00:25:34Z

Links: CVE-2026-17936 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T06:15:12Z

Weaknesses
  • CWE-1021

    Improper Restriction of Rendered UI Layers or Frames

  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-693

    Protection Mechanism Failure