CVE-2026-5882
vulnerability analysis and mitigation

Overview

CVE-2026-5882 is an incorrect security UI vulnerability in the Fullscreen component of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. It was reported anonymously on February 2, 2026 (Chromium issue #480993682) and publicly disclosed on April 8, 2026 as part of the Chrome 147 stable channel release. All versions of Google Chrome prior to 147.0.7727.55 are affected, as is Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's fullscreen mode fails to correctly render or enforce security UI elements, allowing attacker-controlled content to visually impersonate legitimate browser security indicators. An attacker can exploit this by serving a crafted HTML page that, when rendered in fullscreen, displays a spoofed security interface — such as a fake browser chrome, address bar, or security warning — that users cannot easily distinguish from genuine browser UI. Exploitation requires user interaction (e.g., visiting a malicious page and entering fullscreen mode), but no authentication or special privileges are needed on the attacker's side (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation enables a remote attacker to deceive users into believing they are interacting with legitimate browser security features or trusted website elements when they are actually viewing attacker-controlled content rendered in fullscreen. This can facilitate phishing attacks, credential theft, and other social engineering scenarios where users are manipulated by a false security UI. There is no direct impact on confidentiality or availability; the integrity impact is limited to user deception rather than data modification (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious HTML page: Develop an HTML page that uses the Fullscreen API (element.requestFullscreen()) to enter fullscreen mode and renders attacker-controlled content designed to mimic legitimate browser UI elements (e.g., a fake address bar, security warning dialog, or login prompt).
  2. Lure the victim: Distribute the malicious URL via phishing email, social media, or malvertising to direct target users to the crafted page.
  3. Trigger fullscreen mode: The page automatically or via user interaction (e.g., a button click) invokes the Fullscreen API, causing Chrome to enter fullscreen and display the spoofed UI.
  4. Exploit the UI misrepresentation: Due to the incorrect security UI rendering in Chrome's fullscreen component, the attacker's fake interface is displayed without adequate browser-level indicators that would alert the user to the spoofing.
  5. Harvest credentials or perform social engineering: The victim, believing they are interacting with a legitimate browser or website security prompt, enters credentials or takes other actions that benefit the attacker (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from user workstations to unfamiliar domains shortly after visiting a new or suspicious URL; HTTP requests to pages that immediately invoke the Fullscreen API.
  • Logs: Browser history or proxy logs showing visits to pages with embedded requestFullscreen() calls from untrusted or newly registered domains.
  • User Reports: End-user reports of unexpected fullscreen browser behavior, unfamiliar login prompts appearing in fullscreen, or difficulty exiting fullscreen mode on unfamiliar websites.

Mitigation and workarounds

Update Google Chrome to version 147.0.7727.55 or later on all affected systems (Windows, Mac, and Linux); this version contains the fix for CVE-2026-5882 (Chrome Releases). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Microsoft MSRC). Enable automatic browser updates to ensure timely patching, and educate users to be cautious when websites request fullscreen mode and to use the Escape key or F11 to exit fullscreen if unexpected UI appears.

Community reactions

The vulnerability was part of a large Chrome 147 security release that addressed over 60 vulnerabilities, including two critical WebML flaws, which drew broader industry attention (GBHackers). Security monitoring platforms including Tenable (Nessus) and Qualys added detection plugins for CVE-2026-5882 shortly after disclosure. No notable individual researcher commentary or significant social media discussion specific to this CVE has been identified, consistent with its medium severity rating and lack of active exploitation.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management