CVE-2026-5891
vulnerability analysis and mitigation

Overview

CVE-2026-5891 is a UI spoofing vulnerability caused by insufficient policy enforcement in the browser UI of Google Chrome. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux. The vulnerability was reported by researcher Tianyi Hu on February 25, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where Chrome's browser UI fails to properly enforce policies when the renderer process has been compromised. An attacker who has already achieved renderer process compromise can serve a crafted HTML page that manipulates or spoofs browser UI elements, misleading users about the true origin or nature of content they are viewing. Exploitation requires prior renderer compromise and user interaction (e.g., visiting a malicious page), making it a post-exploitation technique rather than a standalone initial access vector. The Chromium issue tracker entry is referenced at https://issues.chromium.org/issues/487471101, though details remain restricted (Chrome Releases, GitHub Advisory).

Impact

A remote attacker who has compromised the renderer process can craft a malicious HTML page to spoof browser UI elements, potentially deceiving users into believing they are interacting with legitimate browser chrome (e.g., address bar, security indicators, or dialog boxes) when they are actually viewing attacker-controlled content. This could facilitate phishing attacks, credential theft, or other social engineering exploits. The CVSS scoring reflects no confidentiality or integrity impact directly, but only a low availability impact; however, the real-world risk lies in enabling deceptive user interactions that could lead to downstream compromise (GitHub Advisory, Feedly).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Users and organizations should update all Chrome installations to version 147.0.7727.55 or later immediately. Enabling automatic updates for Chrome is strongly recommended to ensure timely receipt of future security patches. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update as the underlying Chromium engine is affected (Chrome Releases, Microsoft MSRC).

Community reactions

The Chrome 147 release was covered by security-focused outlets including GBHackers, which highlighted the broader set of critical and high-severity fixes in the update. The vulnerability itself, rated Medium severity, did not generate significant standalone commentary, consistent with its exploitation precondition of requiring a prior renderer compromise. Downstream Linux distributions including Debian and openSUSE issued advisories for their Chromium packages following the upstream fix (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management