CVE-2026-5898
vulnerability analysis and mitigation

Overview

CVE-2026-5898 is an incorrect security UI vulnerability in the Omnibox (address bar) component of Google Chrome on iOS, classified under CWE-451 (User Interface Misrepresentation of Critical Information). It was reported by researcher saidinahikam032 on 2025-12-19 and publicly disclosed on April 7–8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome on iOS versions prior to 147.0.7727.55, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 4.3 (Medium severity) (Chrome Releases, GitHub Advisory).

Technical details

The root cause is improper rendering of security-critical information in Chrome's Omnibox (address bar) on iOS, classified as CWE-451 (User Interface Misrepresentation of Critical Information). A remote attacker can craft a malicious HTML page that, when visited by a user, causes the Omnibox to display incorrect or misleading security indicators — such as falsely representing a site's origin, protocol, or security status. Exploitation requires user interaction (e.g., visiting a crafted page) but no special privileges. The Chromium issue tracker entry is referenced as issue 470295118, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to perform UI spoofing, deceiving users about the security status or origin of the website they are visiting. This can lead to phishing attacks where users are tricked into believing they are on a legitimate or secure site, potentially resulting in credential theft or submission of sensitive information to a malicious server. The impact is limited to integrity (low) with no direct confidentiality or availability impact, but the social engineering potential makes it a meaningful enabler for phishing campaigns targeting iOS Chrome users (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Craft a malicious HTML page: The attacker creates a web page designed to trigger the incorrect Omnibox rendering behavior in Chrome on iOS, potentially manipulating how the address bar displays the URL or security indicators.
  2. Deliver the link to the target: The attacker distributes the link via phishing email, SMS, social media, or other social engineering channels targeting iOS Chrome users.
  3. Victim visits the page: When the victim opens the crafted page in Google Chrome on iOS (prior to version 147.0.7727.55), the Omnibox displays misleading security UI — for example, showing a trusted-looking URL or a false secure connection indicator.
  4. Phishing/credential harvesting: The victim, deceived by the spoofed security UI, interacts with the malicious page as if it were legitimate, potentially submitting credentials or sensitive data to the attacker-controlled server (Chrome Releases, GitHub Advisory).

Mitigation and workarounds

Google has released a patch in Chrome version 147.0.7727.55 for iOS, which addresses this vulnerability. Users should update Google Chrome on iOS devices to version 147.0.7727.55 or later immediately. As a temporary precaution for users unable to update, exercise caution when visiting unfamiliar websites and manually verify the address bar content before entering sensitive information. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update (Chrome Releases, Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader reporting on the Chrome 147 security update, which included over 60 fixes including two critical WebML flaws. Security news outlets such as GBHackers noted the large number of vulnerabilities addressed in this release. The vulnerability itself, rated Low severity by Chromium, did not generate significant standalone commentary, with most attention focused on the higher-severity issues in the same update (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management