
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5880 is an incorrect security UI vulnerability (Omnibox spoofing) in Google Chrome's browser UI component, classified under insufficient policy enforcement. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported anonymously on 2025-06-14 and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where Chrome's browser UI fails to enforce sufficient policy controls to prevent manipulation of the Omnibox (address bar) display. Exploitation requires that an attacker has already compromised the renderer process — a significant precondition — after which a crafted HTML page can be used to cause the Omnibox to display a spoofed URL, deceiving the user about the actual origin of the page. The Chromium issue tracker references bug ID 424995036, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
The primary impact is an integrity violation: users are deceived about the website they are visiting because the Omnibox displays a spoofed URL rather than the true destination. This enables phishing attacks where a victim, already on a compromised page, believes they are on a trusted site (e.g., a banking or authentication portal), potentially leading to credential theft or sensitive data disclosure. There is no direct confidentiality or availability impact from this vulnerability alone, but it can serve as a facilitating component in a broader attack chain (GitHub Advisory, Chrome Releases).
Update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux), which contains the fix for this vulnerability (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). No configuration-based workaround is available; patching is the only remediation. Organizations should prioritize this update particularly for endpoints exposed to phishing campaigns, and ensure Chrome's automatic update mechanism is enabled.
The vulnerability was part of a large Chrome 147 security release that included two Critical-severity WebML flaws (CVE-2026-5858, CVE-2026-5859), which drew more significant attention from the security community. CVE-2026-5880 itself received limited individual commentary given its Medium severity and the high precondition of requiring a prior renderer compromise. Security news outlets such as GBHackers covered the broader Chrome 147 update, noting the volume of fixes (GBHackers). No notable individual researcher commentary specific to CVE-2026-5880 has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."