CVE-2026-5880
vulnerability analysis and mitigation

Overview

CVE-2026-5880 is an incorrect security UI vulnerability (Omnibox spoofing) in Google Chrome's browser UI component, classified under insufficient policy enforcement. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported anonymously on 2025-06-14 and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where Chrome's browser UI fails to enforce sufficient policy controls to prevent manipulation of the Omnibox (address bar) display. Exploitation requires that an attacker has already compromised the renderer process — a significant precondition — after which a crafted HTML page can be used to cause the Omnibox to display a spoofed URL, deceiving the user about the actual origin of the page. The Chromium issue tracker references bug ID 424995036, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).

Impact

The primary impact is an integrity violation: users are deceived about the website they are visiting because the Omnibox displays a spoofed URL rather than the true destination. This enables phishing attacks where a victim, already on a compromised page, believes they are on a trusted site (e.g., a banking or authentication portal), potentially leading to credential theft or sensitive data disclosure. There is no direct confidentiality or availability impact from this vulnerability alone, but it can serve as a facilitating component in a broader attack chain (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Achieve renderer compromise: Exploit a separate, higher-severity vulnerability (e.g., a V8 or Blink memory corruption bug) to gain code execution within Chrome's renderer process — this is a mandatory precondition for CVE-2026-5880.
  2. Craft malicious HTML page: Prepare a specially crafted HTML page that leverages the insufficient policy enforcement in Chrome's browser UI to manipulate the Omnibox display.
  3. Deliver to target: Lure the victim to visit the attacker-controlled page via phishing email, malicious advertisement, or compromised website.
  4. Trigger Omnibox spoofing: Once the renderer is compromised and the crafted page is loaded, the browser UI displays a fake URL in the address bar (e.g., a trusted banking or identity provider domain) while the actual content is attacker-controlled.
  5. Harvest credentials or data: The victim, believing they are on a legitimate site based on the spoofed URL, submits credentials or sensitive information that is captured by the attacker (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux), which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). No configuration-based workaround is available; patching is the only remediation. Organizations should prioritize this update particularly for endpoints exposed to phishing campaigns, and ensure Chrome's automatic update mechanism is enabled.

Community reactions

The vulnerability was part of a large Chrome 147 security release that included two Critical-severity WebML flaws (CVE-2026-5858, CVE-2026-5859), which drew more significant attention from the security community. CVE-2026-5880 itself received limited individual commentary given its Medium severity and the high precondition of requiring a prior renderer compromise. Security news outlets such as GBHackers covered the broader Chrome 147 update, noting the volume of fixes (GBHackers). No notable individual researcher commentary specific to CVE-2026-5880 has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management