CVE-2026-5875
vulnerability analysis and mitigation

Overview

CVE-2026-5875 is a policy bypass vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Lyra Rebane (rebane2001) on 2025-07-08 and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Medium severity by the Chromium security team (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key), stemming from a policy bypass in Chrome's Blink rendering engine that fails to properly enforce browser security policies when processing certain HTML content. An unauthenticated remote attacker can exploit this by crafting a malicious HTML page that, when visited by a victim, causes Blink to bypass intended rendering or display policies, enabling UI spoofing. Exploitation requires user interaction — specifically, a victim must navigate to or open the attacker-controlled page. The Chromium issue tracker references bug ID 430198264 for this vulnerability (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows an attacker to spoof browser UI elements, potentially deceiving users into believing they are interacting with a legitimate website or browser interface. This can facilitate phishing attacks, credential theft, and social engineering by presenting fake security indicators, address bar content, or dialog boxes. The vulnerability has no direct confidentiality or availability impact; the primary risk is integrity-related through user deception, with a CVSS integrity impact rated Low and no confidentiality or availability impact (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Craft a malicious HTML page: The attacker creates a specially crafted HTML page that exploits the Blink policy bypass to manipulate rendered UI elements, such as spoofing address bar content, security indicators, or dialog boxes.
  2. Deliver the page to the victim: The attacker distributes the malicious URL via phishing emails, social media, or malicious advertisements to lure the target into visiting the page using a vulnerable Chrome version (prior to 147.0.7727.55).
  3. Victim visits the page: When the victim opens the crafted HTML page in a vulnerable Chrome browser, Blink processes the content and bypasses the intended security policy, rendering spoofed UI elements.
  4. UI spoofing achieved: The victim sees a falsified browser interface — such as a fake login prompt, spoofed origin indicator, or deceptive security dialog — and may be deceived into submitting credentials or taking other harmful actions (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Chrome immediately to version 147.0.7727.55 or later via the browser's built-in update mechanism or by enabling automatic updates. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a general precaution, users should avoid clicking untrusted links and be alert to social engineering attempts that leverage UI spoofing (Chrome Releases, Microsoft MSRC).

Community reactions

Security news outlets such as GBHackers covered this vulnerability as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. The vulnerability was also noted in Linux distribution security advisories for Debian, openSUSE, and Fedora as Chromium packages were updated. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-5875 has been identified beyond standard vulnerability tracking (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management