
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5899 is an insufficient policy enforcement vulnerability in the History Navigation component of Google Chrome, classified by Google as "Incorrect security UI in History Navigation." It allows a remote attacker who convinces a user to perform specific UI gestures to inject arbitrary scripts or HTML via a crafted HTML page, constituting a Universal Cross-Site Scripting (UXSS) attack. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It was reported by Islam Rzayev on January 11, 2026, and patched with the Chrome 147 stable channel release on April 7, 2026. The CVSS v3.1 base score is 6.1 (Medium) (Chrome Release, GitHub Advisory).
The root cause is an Origin Validation Error (CWE-346) — Chrome's History Navigation component fails to properly enforce same-origin policies, allowing script or HTML content from one origin to be injected into the context of another. The attack vector is network-based and requires no privileges, but does require user interaction: the attacker must convince the victim to perform specific UI gestures (e.g., navigating back/forward in browser history) while visiting a crafted HTML page. This insufficient policy enforcement enables UXSS, bypassing the browser's same-origin policy protections. The Chromium issue tracker reference is bug #474817168, though full technical details remain restricted pending broad user patching (Chrome Release, GitHub Advisory).
Successful exploitation enables Universal Cross-Site Scripting (UXSS), allowing an attacker to inject and execute arbitrary scripts or HTML in the context of any origin the victim visits, effectively bypassing the browser's same-origin policy. This can lead to session hijacking, credential theft, cookie exfiltration, malware distribution, or manipulation of web content across sites. The scope is changed (affecting resources beyond the vulnerable component), with low confidentiality and low integrity impact, and no direct availability impact (GitHub Advisory, Feedly).
The primary remediation is to upgrade Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux), which was released on April 7, 2026 (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update as referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). Organizations should enforce browser update policies to ensure timely patching across all endpoints, and educate users to be cautious when navigating to untrusted websites and to avoid unexpected UI interactions during browsing sessions.
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical Chrome flaws patched in this update. The vulnerability was also noted in Linux distribution security advisories (Debian, openSUSE, Fedora) as part of Chromium package updates. Given its "Low" Chromium severity rating and lack of public PoC, community reaction has been measured, with most attention focused on the two Critical-rated WebML vulnerabilities (CVE-2026-5858, CVE-2026-5859) in the same release (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."