
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5901 is a policy bypass vulnerability in Google Chrome's DevTools component that allows an attacker who convinces a user to install a malicious Chrome extension to bypass enterprise host restrictions for cookie modification. It affects Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based). The vulnerability was reported by Povcfe of Tencent Security Xuanwu Lab on January 29, 2026, and patched in Chrome 147.0.7727.55 released on April 7, 2026. It carries a CVSS v3.1 base score of 6.5 (Medium) and is rated Low severity by Chromium's internal severity scale (Chrome Release, GitHub Advisory).
The root cause is classified as CWE-602 (Client-Side Enforcement of Server-Side Security), where Chrome's DevTools component insufficiently enforces enterprise policies that are intended to restrict cookie modification on specific hosts. A crafted Chrome Extension can leverage DevTools APIs to circumvent these server-side security controls, which are enforced only at the client level. Exploitation requires user interaction — specifically, the victim must be convinced to install a malicious extension — making the attack vector network-based but socially engineered. The Chromium bug tracker entry is issue #479673903, though full technical details remain restricted (Chrome Release, GitHub Advisory).
Successful exploitation allows an attacker to bypass enterprise security policies that restrict cookie modification on designated hosts, potentially enabling session hijacking, credential theft, or unauthorized access to web applications within an enterprise environment. The primary impact is on integrity (CVSS integrity impact: High), as cookies can be modified without authorization; there is no direct confidentiality or availability impact. In enterprise contexts, this bypass could undermine access controls protecting sensitive internal web applications, with potential for lateral movement if session tokens are hijacked (GitHub Advisory, Feedly).
chrome.debugger or cookies API) to interact with restricted hosts and modify cookies in ways that enterprise policies are intended to prevent.cookies, debugger, or host permissions).cookies, debugger, or broad host permissions (<all_urls>) in enterprise-managed environments.Users and administrators should upgrade Google Chrome to version 147.0.7727.55 or later (147.0.7727.55/56 on Windows/Mac, 147.0.7727.55 on Linux); Microsoft Edge (Chromium-based) users should apply the corresponding Microsoft security update. As a workaround, enterprise administrators should enforce Chrome extension management policies to restrict installation to an approved allowlist and audit existing extensions for suspicious permissions. User education about the risks of installing extensions from untrusted sources is also recommended (Chrome Release, Microsoft MSRC).
The vulnerability was covered as part of broader reporting on the Chrome 147 security update, which included over 60 fixes including two critical WebML flaws. Security news outlets such as GBHackers noted the large number of fixes in this release. The Chromium security team rated this specific issue as Low severity, reflecting its social engineering prerequisite and limited direct impact compared to other vulnerabilities in the same release (Chrome Release).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."