
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5881 is a policy bypass vulnerability in the LocalNetworkAccess component of Google Chrome that allows a remote attacker to bypass navigation restrictions via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "asnine" on 2025-10-22 and publicly disclosed on April 8, 2026, when Google released Chrome 147.0.7727.55. It carries a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-284 (Improper Access Control) and resides in Chrome's LocalNetworkAccess policy enforcement mechanism, which is designed to prevent public web pages from making unauthorized requests to private or local network resources. Due to insufficient policy enforcement, a remote attacker can craft a malicious HTML page that circumvents these navigation restrictions, effectively bypassing the browser's security boundary between public internet content and local network resources. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled HTML page — but no privileges are required on the attacker's side. The Chromium issue tracker references bug ID 454162508 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation primarily affects integrity, with a high integrity impact and no direct confidentiality or availability impact per the CVSS scoring. An attacker who tricks a user into visiting a crafted HTML page could bypass Chrome's LocalNetworkAccess restrictions, potentially enabling unauthorized navigation to or interaction with local network resources (e.g., routers, IoT devices, internal web services) that should be inaccessible from public web content. This could facilitate further attacks against internal network assets, such as CSRF-style attacks against local services or reconnaissance of private network topology (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and organizations should update Google Chrome to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Organizations should enforce automated browser update policies to ensure timely patching across all endpoints (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that addressed over 60 vulnerabilities, including two Critical-severity WebML flaws, which drew broader industry attention. Coverage from security outlets such as GBHackers highlighted the overall Chrome 147 update, though CVE-2026-5881 itself, rated Medium severity, did not generate significant standalone commentary. The Chromium security team rated it "Medium" severity, consistent with the CVSS score (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."