CVE-2026-5899
vulnerability analysis and mitigation

Overview

CVE-2026-5899 is an insufficient policy enforcement vulnerability in the History Navigation component of Google Chrome, classified by Google as "Incorrect security UI in History Navigation." It allows a remote attacker who convinces a user to perform specific UI gestures to inject arbitrary scripts or HTML via a crafted HTML page, constituting a Universal Cross-Site Scripting (UXSS) attack. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It was reported by Islam Rzayev on January 11, 2026, and patched with the Chrome 147 stable channel release on April 7, 2026. The CVSS v3.1 base score is 6.1 (Medium) (Chrome Release, GitHub Advisory).

Technical details

The root cause is an Origin Validation Error (CWE-346) — Chrome's History Navigation component fails to properly enforce same-origin policies, allowing script or HTML content from one origin to be injected into the context of another. The attack vector is network-based and requires no privileges, but does require user interaction: the attacker must convince the victim to perform specific UI gestures (e.g., navigating back/forward in browser history) while visiting a crafted HTML page. This insufficient policy enforcement enables UXSS, bypassing the browser's same-origin policy protections. The Chromium issue tracker reference is bug #474817168, though full technical details remain restricted pending broad user patching (Chrome Release, GitHub Advisory).

Impact

Successful exploitation enables Universal Cross-Site Scripting (UXSS), allowing an attacker to inject and execute arbitrary scripts or HTML in the context of any origin the victim visits, effectively bypassing the browser's same-origin policy. This can lead to session hijacking, credential theft, cookie exfiltration, malware distribution, or manipulation of web content across sites. The scope is changed (affecting resources beyond the vulnerable component), with low confidentiality and low integrity impact, and no direct availability impact (GitHub Advisory, Feedly).

Exploitation steps

  1. Craft a malicious HTML page: Develop a web page that exploits Chrome's History Navigation policy enforcement flaw, designed to trigger UXSS when the victim performs specific browser history UI gestures (e.g., clicking the back or forward button).
  2. Social engineering: Lure the target user to visit the malicious page via phishing email, malicious advertisement, or compromised website link.
  3. Induce UI gestures: Prompt the user to interact with browser history navigation controls (e.g., through deceptive UI elements that encourage clicking back/forward), triggering the insufficient policy enforcement flaw.
  4. Inject arbitrary scripts/HTML: The crafted page exploits the origin validation error to inject malicious scripts or HTML into the context of another origin loaded in the browser's history.
  5. Achieve objective: The injected script executes in the victim's browser under a trusted origin, enabling session cookie theft, credential harvesting, or further client-side attacks (Chrome Release, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser to unknown or suspicious domains following history navigation actions; unusual POST requests containing encoded script payloads.
  • Logs: Browser console errors related to cross-origin script execution or policy violations; access logs showing navigation to suspicious or newly registered domains.
  • Process: Unexpected browser child processes or network activity initiated after back/forward navigation events on untrusted sites.
  • File System: Unexpected files written to browser profile directories (e.g., cookies, local storage modifications) following visits to suspicious pages.

Mitigation and workarounds

The primary remediation is to upgrade Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux), which was released on April 7, 2026 (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding Edge update as referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). Organizations should enforce browser update policies to ensure timely patching across all endpoints, and educate users to be cautious when navigating to untrusted websites and to avoid unexpected UI interactions during browsing sessions.

Community reactions

The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader set of critical Chrome flaws patched in this update. The vulnerability was also noted in Linux distribution security advisories (Debian, openSUSE, Fedora) as part of Chromium package updates. Given its "Low" Chromium severity rating and lack of public PoC, community reaction has been measured, with most attention focused on the two Critical-rated WebML vulnerabilities (CVE-2026-5858, CVE-2026-5859) in the same release (Chrome Release).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management