
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5876 is a side-channel information leakage vulnerability in the Navigation component of Google Chrome that allows a remote attacker to leak cross-origin data via a crafted HTML page. It was reported by security researcher Lyra Rebane (rebane2001) on December 18, 2023, and patched with the release of Chrome 147.0.7727.55 on April 1, 2026, with public disclosure on April 8, 2026. Affected products include Google Chrome prior to version 147.0.7727.55 and Microsoft Edge (Chromium-based). The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified under CWE-1300 (Improper Protection of Physical Side Channels), reflecting insufficient protections in Chrome's Navigation component that allow observable behavioral differences to be exploited for information inference. An attacker can craft a malicious HTML page that, when visited by a victim, exploits timing or behavioral side-channel signals in the browser's navigation logic to infer cross-origin data that should be protected by the Same-Origin Policy. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no special privileges or authentication are needed on the attacker's side. The Chromium issue tracker references bug ID 41485206, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to leak sensitive cross-origin data from other websites the victim has visited or is authenticated to, undermining the browser's Same-Origin Policy protections. The impact is limited to confidentiality — there is no integrity or availability impact — but the exposed data could include session tokens, personal information, or other sensitive content from third-party origins. This type of cross-origin data leakage could facilitate further attacks such as session hijacking or targeted phishing if combined with other techniques (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7–8, 2026. Microsoft Edge (Chromium-based) users should apply the corresponding Edge update that incorporates the Chromium 147 fixes. No configuration-based workaround is available; updating to the patched version is the only recommended remediation. Organizations should prioritize this update as part of their regular browser patching cycle, particularly for endpoints that regularly access sensitive web applications (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that included two Critical-severity WebML flaws (CVE-2026-5858, CVE-2026-5859), which drew more community attention than CVE-2026-5876 itself. Security news outlets such as GBHackers covered the broader Chrome 147 update, noting the volume of fixes (60+ vulnerabilities). The vulnerability received a $2,000 bug bounty reward from Google, reflecting its Medium severity classification. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-5876 has been identified (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."