
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5878 is an incorrect security UI vulnerability in the Blink rendering engine of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported by Shaheen Fazim on September 6, 2024 (Chromium issue #365089001) and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55 on Windows, Mac, and Linux; Microsoft Edge (Chromium-based) is also listed as an affected product. The vulnerability carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's Blink engine does not correctly render or enforce security-relevant UI elements, allowing attacker-controlled content to obscure or spoof them. An unauthenticated remote attacker can exploit this by hosting a crafted HTML page that manipulates how Blink presents security indicators or dialogs to the user; exploitation requires the victim to visit the malicious page (user interaction required). The Chromium bug tracker entry (issue #365089001) is referenced but access to full technical details remains restricted pending broad user update adoption (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker to spoof Chrome's security user interface, potentially deceiving users into believing they are interacting with legitimate browser security dialogs, warnings, or permission prompts. This can facilitate social engineering attacks such as credential harvesting, phishing, or manipulation of user decisions regarding security-sensitive actions. The CVSS scoring reflects a low integrity impact with no direct confidentiality or availability impact, but the real-world risk is amplified by the potential for user manipulation at scale (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and organizations should update all Chrome installations to version 147.0.7727.55 or later immediately; enterprise deployments should enforce automated updates or manually deploy the patched version. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that included two critical WebML flaws and over 60 total fixes, which drew broader security community attention to the update (Chrome Releases). Coverage appeared across security news outlets and Linux distribution advisories (Debian, openSUSE, FreeBSD), reflecting standard patch-cycle tracking rather than heightened concern specific to this CVE. No notable researcher commentary or significant social media discussion specific to CVE-2026-5878 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."