CVE-2026-3941 identifies a low-severity vulnerability in Google Chrome's DevTools, affecting versions prior to 146.0.7680.71 across Apple, Google, Linux, and Microsoft platforms. This flaw stems from insufficient policy enforcement, allowing a remote attacker to bypass navigation restrictions via a crafted HTML page. With a CVSS score of 4.3 (Medium), it requires user interaction and has low attack complexity, resulting in a low integrity impact. There is currently no evidence of active exploitation, nor is public exploit code available, though it has garnered some community discussion and minor media coverage related to security updates.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 146.0.7680.71, < 146.0.7680.71CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 146.0.7680.71CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.