
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5882 is an incorrect security UI vulnerability in the Fullscreen component of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported anonymously on February 2, 2026 (Chromium issue #480993682) and publicly disclosed on April 8, 2026 as part of the Chrome 147 stable channel release. All versions of Google Chrome prior to 147.0.7727.55 are affected, as is Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's fullscreen mode fails to correctly render or enforce security UI elements, allowing attacker-controlled content to visually impersonate legitimate browser security indicators. An attacker can exploit this by serving a crafted HTML page that, when rendered in fullscreen, displays a spoofed security interface — such as a fake browser chrome, address bar, or security warning — that users cannot easily distinguish from genuine browser UI. Exploitation requires user interaction (e.g., visiting a malicious page and entering fullscreen mode), but no authentication or special privileges are needed on the attacker's side (Chrome Releases, GitHub Advisory).
Successful exploitation enables a remote attacker to deceive users into believing they are interacting with legitimate browser security features or trusted website elements when they are actually viewing attacker-controlled content rendered in fullscreen. This can facilitate phishing attacks, credential theft, and other social engineering scenarios where users are manipulated by a false security UI. There is no direct impact on confidentiality or availability; the integrity impact is limited to user deception rather than data modification (GitHub Advisory, Feedly).
element.requestFullscreen()) to enter fullscreen mode and renders attacker-controlled content designed to mimic legitimate browser UI elements (e.g., a fake address bar, security warning dialog, or login prompt).requestFullscreen() calls from untrusted or newly registered domains.Update Google Chrome to version 147.0.7727.55 or later on all affected systems (Windows, Mac, and Linux); this version contains the fix for CVE-2026-5882 (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Microsoft MSRC). Enable automatic browser updates to ensure timely patching, and educate users to be cautious when websites request fullscreen mode and to use the Escape key or F11 to exit fullscreen if unexpected UI appears.
The vulnerability was part of a large Chrome 147 security release that addressed over 60 vulnerabilities, including two critical WebML flaws, which drew broader industry attention (GBHackers). Security monitoring platforms including Tenable (Nessus) and Qualys added detection plugins for CVE-2026-5882 shortly after disclosure. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its medium severity rating and lack of active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."