CVE-2024-7017 Details
Description
Inappropriate implementation in DevTools in Google Chrome prior to 126.0.6478.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
A vulnerability in the DevTools component of Google Chrome, in versions prior to 126.0.6478.182, allowed remote attackers to potentially escape the sandbox by exploiting a race condition in the DevTools API. This was achieved by an extension with the 'devtools_page' permission, which could execute arbitrary JavaScript on privileged pages such as 'chrome://policy'. The vulnerability stemmed from insufficient checks in the DevTools API, particularly in the 'chrome.devtools.inspectedWindow.reload' function, which failed to properly validate permissions before executing scripts on inspected pages.
Users can update to Google Chrome version 126.0.6478.182 or later, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Nov 15, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://chromereleases.googleblog.com/2024/07/stable-channel-update-for-desktop.html | [email protected] | Release NotesVendor Advisory |
| https://issues.chromium.org/issues/338248595 | [email protected] | ExploitIssue TrackingThird Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-362 | Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| google chrome | < 126.0.6478.182 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
| linux linux kernel | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 17, 2025 | Initial Analysis | [email protected] |
| Nov 14, 2025 | CVE Modified | CISA-ADP |
| Nov 14, 2025 | New CVE Received | [email protected] |