
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5906 is an incorrect security UI vulnerability in the Omnibox (URL bar) of Google Chrome on Android, classified under CWE-451 (User Interface Misrepresentation of Critical Information). It was reported by researcher mohamedhesham9173 on 2026-02-13 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. The vulnerability affects Google Chrome on Android prior to version 147.0.7727.55, and Microsoft Edge (Chromium-based) is also listed as an affected product. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Release, GitHub Advisory).
The root cause is improper representation of critical security information in Chrome's Omnibox component on Android (CWE-451), allowing the displayed URL to be spoofed. A remote attacker can craft a malicious HTML page that, when visited by a user, causes the Omnibox to display a misleading or falsified URL rather than the actual page origin. Exploitation requires user interaction — specifically, a victim must navigate to or be redirected to the attacker-controlled page. No technical write-ups or public proof-of-concept code have been identified at this time (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to spoof the contents of the Chrome Omnibox (URL bar) on Android devices, deceiving users into believing they are visiting a legitimate website when they are actually on a malicious one. The primary risk is enabling phishing attacks targeting credentials, financial information, or other sensitive data. There is no direct impact on system confidentiality or availability — the integrity impact is limited to user interface deception rather than data or system compromise (GitHub Advisory, Chrome Release).
Google has addressed this vulnerability in Chrome version 147.0.7727.55 for Android, released on April 7, 2026. Users should update Google Chrome on Android to version 147.0.7727.55 or later immediately. Enabling automatic updates is recommended to ensure timely patching of future vulnerabilities. As a behavioral mitigation, users should be educated to verify URLs carefully before entering sensitive information, particularly on mobile devices where the address bar may be less visible (Chrome Release).
The vulnerability was covered as part of broader reporting on the Chrome 147 update, which patched over 60 vulnerabilities including two critical WebML flaws. Security news outlets such as GBHackers noted the significance of the overall Chrome 147 release, though CVE-2026-5906 itself received limited individual attention given its Low severity rating. No notable researcher commentary or significant community discussion specific to this CVE has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."