
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5892 is an insufficient policy enforcement vulnerability in Progressive Web Apps (PWAs) in Google Chrome that allows a remote attacker who has already compromised the renderer process to silently install a PWA without user consent via a crafted HTML page. The vulnerability was reported by Tianyi Hu on February 25, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 6.6 (Medium) (Chrome Releases, GitHub Advisory).
The root cause is classified as CWE-1268 (Policy Privileges are not Assigned Consistently Between Control and Data Agents), meaning Chrome's PWA installation policy is not uniformly enforced between the browser's control plane and the renderer process (GitHub Advisory). Exploitation requires the attacker to have already compromised the renderer process — a significant precondition — after which a crafted HTML page can trigger a PWA installation bypassing the normal user consent prompt. The attack vector is local (AV:L), requires low privileges and user interaction, and does not result in a scope change. The Chromium issue tracker entry (issue #487568011) is currently restricted pending broad user adoption of the patch (Chrome Releases).
Successful exploitation allows an attacker with a compromised renderer process to covertly install a malicious PWA on the victim's system without their knowledge or explicit consent, resulting in high integrity and high availability impact with no direct confidentiality impact per the CVSS scoring (GitHub Advisory). A silently installed malicious PWA could persist on the user's system, potentially serving as a foothold for further malicious activity, displaying phishing content, or disrupting normal browser/application behavior. The scope is limited to the affected user's session and local system, with no direct lateral movement capability inherent to this vulnerability alone.
Update Google Chrome to version 147.0.7727.55 or later on Windows, Mac, and Linux; this version was promoted to the stable channel on April 7, 2026 (Chrome Releases). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update addressing this CVE (Microsoft MSRC). Organizations should enforce automatic browser updates across all endpoints and monitor for unexpected PWA installations on user systems as a precautionary measure. No configuration-based workaround is known; patching is the only remediation.
The vulnerability was covered as part of broader reporting on the Chrome 147 security release, which included over 60 fixes including two critical WebML flaws that drew more attention (GBHackers). Security community coverage was routine, with no notable researcher commentary or significant social media discussion specific to CVE-2026-5892 given its medium severity and the high precondition of a prior renderer compromise. Downstream Linux distributions including Debian and openSUSE issued advisories for their Chromium packages incorporating this fix (Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."