
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5905 is an incorrect security UI vulnerability in the Permissions component of Google Chrome on Windows that allows a remote attacker to perform domain spoofing via a crafted HTML page. It was reported by researcher "daffainfo" on 2026-02-12 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55 on Windows; Microsoft Edge (Chromium-based) is also affected. Google rates this as Low severity, with a CVSS v3.1 base score of 6.5 (Medium) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-451 (User Interface Misrepresentation of Critical Information), meaning Chrome's Permissions UI fails to accurately represent security-critical information to the user, allowing the origin or identity of a requesting site to be obscured or spoofed. An attacker can exploit this by crafting a malicious HTML page that, when visited by a victim, causes the browser's permissions dialog to display an incorrect or misleading domain name. Exploitation requires user interaction — the victim must visit the attacker-controlled page — but no authentication or special privileges are needed on the attacker's side. The Chromium issue tracker entry is referenced as issue #483899628, though full technical details remain restricted pending broad user patching (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to spoof the domain displayed in Chrome's permissions UI, potentially deceiving users into granting sensitive browser permissions (such as camera, microphone, location, or notifications) to a malicious site while believing they are interacting with a trusted domain. This primarily impacts integrity (CVSS integrity impact: High) and poses a significant phishing and social engineering risk, as users may be misled about which site is requesting access to sensitive resources. There is no direct confidentiality or availability impact, and the vulnerability does not enable code execution or lateral movement on its own (GitHub Advisory, Chrome Releases).
chrome://settings/content) showing permissions granted to unrecognized or suspicious origins.Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac). Users and administrators should update Google Chrome to version 147.0.7727.55 or later immediately. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. Enabling automatic updates is the recommended approach to ensure timely patching. No configuration-based workaround is available; upgrading is the only remediation (Chrome Releases, Microsoft MSRC).
Coverage of CVE-2026-5905 has been largely routine, appearing in aggregated Chrome 147 security update roundups on security news sites such as GBHackers and BeyondMachines, which highlighted the broader batch of 60+ vulnerabilities patched in this release rather than focusing specifically on this low-severity issue. No notable independent researcher commentary or significant social media discussion specific to this CVE has been identified (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."