CVE-2026-5881
vulnerability analysis and mitigation

Overview

CVE-2026-5881 is a policy bypass vulnerability in the LocalNetworkAccess component of Google Chrome that allows a remote attacker to bypass navigation restrictions via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "asnine" on 2025-10-22 and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-284 (Improper Access Control) and resides in Chrome's LocalNetworkAccess policy enforcement mechanism, which is designed to prevent public web pages from making unauthorized requests to private or local network resources. Due to insufficient policy enforcement, a remote attacker can craft a malicious HTML page that circumvents these navigation restrictions, effectively bypassing the browser's security boundary between public internet content and local network resources. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled HTML page — but no privileges are required on the attacker's side. The Chromium issue tracker references bug ID 454162508 for this vulnerability (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation primarily affects integrity, with a high integrity impact and no direct confidentiality or availability impact per the CVSS scoring. An attacker who tricks a user into visiting a crafted HTML page could bypass Chrome's LocalNetworkAccess restrictions, potentially enabling unauthorized navigation to or interaction with local network resources (e.g., routers, IoT devices, internal web services) that should be inaccessible from public web content. This could facilitate further attacks against internal network assets, such as CSRF-style attacks against local services or reconnaissance of private network topology (GitHub Advisory, Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and organizations should update Google Chrome to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Organizations should enforce automated browser update policies to ensure timely patching across all endpoints (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was part of a large Chrome 147 security release that addressed over 60 vulnerabilities, including two Critical-severity WebML flaws, which drew broader industry attention. Coverage from security outlets such as GBHackers highlighted the overall Chrome 147 update, though CVE-2026-5881 itself, rated Medium severity, did not generate significant standalone commentary. The Chromium security team rated it "Medium" severity, consistent with the CVSS score (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management