
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5900 is a policy bypass vulnerability in the Downloads component of Google Chrome that allows a remote attacker to circumvent multi-download protections via a crafted HTML page. It was reported by Luan Herrera (@lbherrera_) on January 13, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. The vulnerability affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 4.3 (Medium) and is rated Low severity by the Chromium security team (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-693 (Protection Mechanism Failure), indicating that Chrome's Downloads subsystem fails to correctly enforce its multi-download protection policy under certain conditions. An attacker can craft a malicious HTML page that, when visited by a user, triggers multiple file downloads while bypassing the browser's built-in safeguards designed to warn or block rapid or suspicious download patterns. Exploitation requires user interaction — specifically, a victim must visit the attacker-controlled page — but no authentication or elevated privileges are needed. The Chromium issue tracker entry (ID 475265304) is currently restricted pending broader user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to silently initiate multiple file downloads on a victim's system without triggering Chrome's protective warnings or blocks. The primary impact is a low-integrity violation — an attacker could facilitate the delivery of potentially malicious files to the user's download directory without the expected user consent prompts. There is no direct confidentiality or availability impact, and the vulnerability does not enable code execution on its own; however, it could serve as a delivery mechanism in a multi-stage attack chain (GitHub Advisory, Feedly).
<a download> elements, programmatic click() triggers, or window.open() calls) designed to initiate multiple simultaneous or rapid file downloads..exe, .msi, .bat, .ps1), scripts, or archive files from unknown sources.chrome://downloads history reflecting bulk downloads not initiated by the user.Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac). Users and organizations should update Chrome to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling automatic browser updates is the most effective long-term mitigation. No configuration-based workaround is available for this vulnerability (Chrome Releases, Microsoft MSRC).
The vulnerability was part of a large Chrome 147 security release that included two Critical-severity WebML flaws, which drew more significant community attention. Coverage from GBHackers and BeyondMachines highlighted the broader Chrome 147 update, noting the volume of fixes (60+ vulnerabilities) rather than focusing specifically on CVE-2026-5900 given its Low severity rating. No notable individual researcher commentary specific to this CVE has been identified beyond the original reporter, Luan Herrera (@lbherrera_), who has a history of reporting Chrome policy bypass issues (GBHackers, Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."