
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5894 is an inappropriate implementation vulnerability in the PDF handling component of Google Chrome that allows a remote attacker to bypass navigation restrictions via a crafted HTML page. It affects Google Chrome versions prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Povcfe of Tencent Security Xuanwu Lab on February 5, 2026, and publicly disclosed on April 7–8, 2026, when Google released Chrome 147. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Release, GitHub Advisory).
The root cause is an improperly implemented security check in Chrome's PDF subsystem (CWE-358: Improperly Implemented Security Check for Standard; CWE-346: Origin Validation Error). The flaw allows a remote attacker to craft a malicious HTML page that, when opened in an affected Chrome version, triggers the PDF component to bypass intended navigation restrictions — potentially enabling unauthorized navigation or manipulation of PDF viewing behavior. Exploitation requires user interaction (visiting a crafted page) but no authentication or elevated privileges. The Chromium issue tracker entry is referenced as issue #481882038, though full technical details remain restricted pending broad user update (Chrome Release, GitHub Advisory).
Successful exploitation has a limited but concrete impact: an attacker can manipulate PDF navigation behavior within Chrome, potentially causing unintended document access or interactions. The vulnerability has no confidentiality or availability impact (CVSS C:N/A:N), with only a low integrity impact (I:L), meaning an attacker could influence what content is navigated to or displayed within a PDF context but cannot directly exfiltrate data or crash the browser. Lateral movement and data exposure risk are minimal given the constrained scope of the PDF navigation bypass (GitHub Advisory, Red Hat Bugzilla).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Organizations should ensure Chrome auto-updates are enabled and verify all endpoints are running version 147.0.7727.55 or later. No configuration-based workaround is available; updating to the patched version is the only remediation (Chrome Release, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that included two Critical-severity WebML flaws (CVE-2026-5858, CVE-2026-5859), which drew more significant community attention. CVE-2026-5894 itself, rated Low severity, received minimal individual commentary given its limited impact. Security news outlets such as GBHackers covered the broader Chrome 147 update, and downstream Linux distributions (Debian, openSUSE, Fedora) issued their own Chromium update advisories. No notable researcher commentary specific to this CVE has been identified (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."