CVE-2026-5905
vulnerability analysis and mitigation

Overview

CVE-2026-5905 is an incorrect security UI vulnerability in the Permissions component of Google Chrome on Windows that allows a remote attacker to perform domain spoofing via a crafted HTML page. It was reported by researcher "daffainfo" on 2026-02-12 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55 on Windows; Microsoft Edge (Chromium-based) is also affected. Google rates this as Low severity, with a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's Permissions UI fails to accurately represent security-critical information to the user, allowing the origin or identity of a requesting site to be obscured or spoofed. An attacker can exploit this by crafting a malicious HTML page that, when visited by a victim, causes the browser's permissions dialog to display an incorrect or misleading domain name. Exploitation requires user interaction — the victim must visit the attacker-controlled page — but no authentication or special privileges are needed on the attacker's side. The Chromium issue tracker entry is referenced as issue #483899628, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to spoof the domain displayed in Chrome's permissions UI, potentially deceiving users into granting sensitive browser permissions (such as camera, microphone, location, or notifications) to a malicious site while believing they are interacting with a trusted domain. This primarily impacts integrity (CVSS integrity impact: High) and poses a significant phishing and social engineering risk, as users may be misled about which site is requesting access to sensitive resources. There is no direct confidentiality or availability impact, and the vulnerability does not enable code execution or lateral movement on its own (GitHub Advisory, Chrome Releases).

Exploitation steps

  1. Craft a malicious HTML page: The attacker creates a web page designed to trigger Chrome's Permissions dialog in a way that exploits the incorrect security UI, causing the displayed domain to appear as a trusted site rather than the attacker's actual domain.
  2. Deliver the link to the victim: The attacker distributes the URL via phishing email, social media, or other means, enticing the victim to visit the page in a vulnerable version of Chrome on Windows (prior to 147.0.7727.55).
  3. Trigger the permissions prompt: When the victim loads the page, Chrome displays a permissions request (e.g., for camera, microphone, location, or notifications) with a spoofed or misleading domain name in the UI.
  4. Victim grants permission: Believing the request originates from a legitimate, trusted domain, the victim clicks "Allow," inadvertently granting the attacker's site access to the requested browser resource.
  5. Abuse granted permissions: The attacker's site leverages the granted permission for surveillance, data collection, or further social engineering (Chrome Releases, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the browser to unfamiliar domains shortly after a permissions grant event; traffic to domains that do not match the site the user intended to visit.
  • Logs: Browser permission grant events (visible in Chrome's site settings at chrome://settings/content) showing permissions granted to unrecognized or suspicious origins.
  • User Reports: Users reporting unexpected permission prompts appearing to come from trusted sites, or noticing camera/microphone/location access indicators active on unfamiliar pages.

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac). Users and administrators should update Google Chrome to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling automatic updates is the recommended approach to ensure timely patching. No configuration-based workaround is available; upgrading is the only remediation (Chrome Releases, Microsoft MSRC).

Community reactions

Coverage of CVE-2026-5905 has been largely routine, appearing in aggregated Chrome 147 security update roundups on security news sites such as GBHackers and BeyondMachines, which highlighted the broader batch of 60+ vulnerabilities patched in this release rather than focusing specifically on this low-severity issue. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management