
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5875 is a policy bypass vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Lyra Rebane (rebane2001) on 2025-07-08 and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Medium severity by the Chromium security team (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), stemming from a policy bypass in Chrome's Blink rendering engine that fails to properly enforce browser security policies when processing certain HTML content. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by a victim, causes Blink to bypass intended rendering or display policies, enabling UI spoofing. Exploitation requires user interaction — specifically, a victim must navigate to or open the attacker-controlled page. The Chromium issue tracker references bug ID 430198264 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker to spoof browser UI elements, potentially deceiving users into believing they are interacting with a legitimate website or browser interface. This can facilitate phishing attacks, credential theft, and social engineering by presenting fake security indicators, address bar content, or dialog boxes. The vulnerability has no direct confidentiality or availability impact; the primary risk is integrity-related through user deception, with a CVSS integrity impact rated Low and no confidentiality or availability impact (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Chrome immediately to version 147.0.7727.55 or later via the browser's built-in update mechanism or by enabling automatic updates. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a general precaution, users should avoid clicking untrusted links and be alert to social engineering attempts that leverage UI spoofing (Chrome Releases, Microsoft MSRC).
Security news outlets such as GBHackers covered this vulnerability as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. The vulnerability was also noted in Linux distribution security advisories for Debian, openSUSE, and Fedora as Chromium packages were updated. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-5875 has been identified beyond standard vulnerability tracking (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."