CVE-2026-3940 describes an insufficient policy enforcement vulnerability within Google Chrome's DevTools, enabling a remote attacker to bypass navigation restrictions through a specially crafted HTML page. This vulnerability affects Chromium-based browsers across various platforms, including Apple, Google, Linux, and Microsoft. It carries a Medium CVSS score of 5.3, indicating a network attack vector with low attack complexity that results in a low integrity impact without requiring user interaction or privileges. Despite some community discussion and media coverage, there is currently no evidence of active exploitation, nor is public exploit code available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.71, < 146.0.7680.71CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.