CVE-2026-5887
vulnerability analysis and mitigation

Overview

CVE-2026-5887 is a medium-severity vulnerability involving insufficient validation of untrusted input in the Downloads component of Google Chrome on Windows. It allows a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability was reported by researcher "daffainfo" on February 20, 2026, and publicly disclosed on April 8, 2026, alongside the Chrome 147 stable channel release. Affected versions are all Google Chrome releases on Windows prior to 147.0.7727.55; Microsoft Edge (Chromium-based) is also listed as an affected product. The CVSS v3.1 base score is 4.3 (Medium) (Chrome Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-20 (Improper Input Validation): Chrome's Downloads subsystem on Windows fails to adequately validate untrusted input, allowing security restrictions to be circumvented. An attacker exploits this by hosting a crafted HTML page that, when visited by a victim, triggers the flawed download validation logic and causes Chrome to permit downloads that would otherwise be blocked by the browser's safety mechanisms. The attack vector is network-based, requires no privileges, but does require user interaction (visiting the malicious page). The Chromium issue tracker reference is bug #486079015, though full technical details remain restricted pending broad user update (Chrome Advisory, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to bypass Chrome's download security restrictions on Windows systems, potentially causing unauthorized or normally-blocked files (such as malware or unwanted software) to be downloaded to the victim's machine. The integrity impact is rated Low, with no direct confidentiality or availability impact. While the vulnerability itself does not grant code execution, it could serve as a stepping stone for delivering malicious payloads to users who visit attacker-controlled pages (GitHub Advisory, Chrome Advisory).

Mitigation and workarounds

Google has patched this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users should update Google Chrome to version 147.0.7727.55 or later immediately, and ensure automatic browser updates are enabled. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; upgrading is the only remediation (Chrome Advisory, Microsoft MSRC).

Community reactions

Coverage of CVE-2026-5887 was largely bundled with the broader Chrome 147 security update, which addressed over 60 vulnerabilities including two Critical-rated WebML flaws. Security news outlets such as GBHackers highlighted the overall Chrome 147 patch batch, with CVE-2026-5887 receiving limited individual attention given its Medium severity rating. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management