CVE-2026-5892
vulnerability analysis and mitigation

Overview

CVE-2026-5892 is an insufficient policy enforcement vulnerability in Progressive Web Apps (PWAs) in Google Chrome that allows a remote attacker who has already compromised the renderer process to silently install a PWA without user consent via a crafted HTML page. The vulnerability was reported by Tianyi Hu on February 25, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 6.6 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is classified as CWE-1268 (Policy Privileges are not Assigned Consistently Between Control and Data Agents), meaning Chrome's PWA installation policy is not uniformly enforced between the browser's control plane and the renderer process (GitHub Advisory). Exploitation requires the attacker to have already compromised the renderer process — a significant precondition — after which a crafted HTML page can trigger a PWA installation bypassing the normal user consent prompt. The attack vector is local (AV:L), requires low privileges and user interaction, and does not result in a scope change. The Chromium issue tracker entry (issue #487568011) is currently restricted pending broad user adoption of the patch (Chrome Releases).

Impact

Successful exploitation allows an attacker with a compromised renderer process to covertly install a malicious PWA on the victim's system without their knowledge or explicit consent, resulting in high integrity and high availability impact with no direct confidentiality impact per the CVSS scoring (GitHub Advisory). A silently installed malicious PWA could persist on the user's system, potentially serving as a foothold for further malicious activity, displaying phishing content, or disrupting normal browser/application behavior. The scope is limited to the affected user's session and local system, with no direct lateral movement capability inherent to this vulnerability alone.

Mitigation and workarounds

Update Google Chrome to version 147.0.7727.55 or later on Windows, Mac, and Linux; this version was promoted to the stable channel on April 7, 2026 (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update addressing this CVE (Microsoft MSRC). Organizations should enforce automatic browser updates across all endpoints and monitor for unexpected PWA installations on user systems as a precautionary measure. No configuration-based workaround is known; patching is the only remediation.

Community reactions

The vulnerability was covered as part of broader reporting on the Chrome 147 security release, which included over 60 fixes including two critical WebML flaws that drew more attention (GBHackers). Security community coverage was routine, with no notable researcher commentary or significant social media discussion specific to CVE-2026-5892 given its medium severity and the high precondition of a prior renderer compromise. Downstream Linux distributions including Debian and openSUSE issued advisories for their Chromium packages incorporating this fix (Linux Security).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management