
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5897 is an incorrect security UI vulnerability in the Downloads component of Google Chrome that allows a remote attacker to perform UI spoofing via a crafted HTML page. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux. It was reported by Farras Givari on 2025-05-24 and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Release, GitHub Advisory).
The root cause is classified as CWE-451 (User Interface Misrepresentation of Critical Information), where Chrome's Downloads UI fails to correctly render or enforce security indicators, allowing attacker-controlled content to spoof the appearance of download prompts or security warnings (GitHub Advisory). Exploitation requires the attacker to host a crafted HTML page and convince a user to perform specific UI gestures (e.g., clicks or interactions) that trigger the incorrect UI rendering in the Downloads component. The attack vector is network-based, requires no privileges, but does require user interaction. The Chromium issue tracker entry (issue #419921726) is currently restricted pending broad user update rollout (Chrome Release).
Successful exploitation allows an attacker to deceive users about the legitimacy of downloads or security warnings displayed in Chrome's Downloads UI, potentially causing users to unknowingly download or execute malicious files. The integrity impact is low and scoped to the affected browser component, with no direct confidentiality or availability impact. There is no evidence of lateral movement potential or direct data exposure beyond the social engineering risk inherent in UI spoofing attacks (GitHub Advisory, Chrome Release).
Update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 for Windows/Mac, 147.0.7727.55 for Linux), which contains the fix for this vulnerability (Chrome Release). Organizations should ensure automatic Chrome updates are enabled via enterprise policy to minimize exposure windows. No configuration-based workaround is available; patching is the only remediation. Microsoft Edge (Chromium-based) users should also monitor for a corresponding Edge update from Microsoft (Microsoft MSRC).
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical and high-severity fixes in the update alongside this lower-severity issue. The vulnerability received routine coverage in Linux distribution security advisories (Debian, openSUSE, Fedora) as part of Chromium package updates. No notable independent researcher commentary or significant social media discussion specific to CVE-2026-5897 has been identified, consistent with its Low/Medium severity rating.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."