Description
Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
Published: 2026-05-06
Score: 3.1 Low
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Chrome’s DevTools policy enforcement allowed a malicious extension that a user installs to bypass navigation restrictions. The vulnerability lets the extension override controls that normally prevent automatic redirects or URL navigation, thereby enabling the delivery of malicious content or phishing payloads. This weakness is an insufficient enforcement of authorization and improper handling of extension privileges.

Affected Systems

Google Chrome versions before 148.0.7778.96 are affected. The issue applies to all desktop installations of Chrome that include the DevTools component, regardless of operating system.

Risk and Exploitability

The CVSS score is 3.1, indicating low severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires a user to be persuaded to install a malicious extension, after which the extension can use the DevTools API to bypass navigation controls. The attack vector therefore depends on social engineering and the availability of a user‑installable extension.

Generated by OpenCVE AI on May 7, 2026 at 03:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Chrome to version 148.0.7778.96 or later.
  • Configure Chrome policies to restrict extension installation to an approved whitelist.
  • Disable or restrict DevTools usage for users who do not require access to the developer tools.

Generated by OpenCVE AI on May 7, 2026 at 03:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6250-1 chromium security update
History

Thu, 07 May 2026 03:45:00 +0000

Type Values Removed Values Added
Title DevTools Policy Enforcement Bypass via Malicious Chrome Extension

Thu, 07 May 2026 01:30:00 +0000

Type Values Removed Values Added
Title DevTools Policy Enforcement Bypass via Malicious Extension
Weaknesses CWE-285

Wed, 06 May 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Wed, 06 May 2026 23:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 06 May 2026 22:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics cvssV3_1

{'score': 3.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N'}


Wed, 06 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Google
Google chrome
Vendors & Products Google
Google chrome

Wed, 06 May 2026 20:15:00 +0000

Type Values Removed Values Added
Title DevTools Policy Enforcement Bypass via Malicious Extension
Weaknesses CWE-285

Wed, 06 May 2026 18:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in DevTools in Google Chrome prior to 148.0.7778.96 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-05-06T21:58:42.236Z

Reserved: 2026-05-05T22:59:14.491Z

Link: CVE-2026-7937

cve-icon Vulnrichment

Updated: 2026-05-06T21:42:15.098Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-06T19:16:42.027

Modified: 2026-05-06T23:34:15.650

Link: CVE-2026-7937

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-07T03:30:20Z

Weaknesses