
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5911 is a Content Security Policy (CSP) bypass vulnerability in the ServiceWorkers component of Google Chrome. It affects all versions of Google Chrome prior to 147.0.7727.55 on Windows, Mac, and Linux, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by researcher "lebr0nli" of National Yang Ming Chiao Tung University's Security and Systems Lab on February 19, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. It carries a CVSS v3.1 base score of 4.3 (Medium), and Chromium's internal severity rating is Low (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-693 (Protection Mechanism Failure), specifically a policy bypass in the ServiceWorkers subsystem of Chromium. A remote attacker can craft a malicious HTML page that, when visited by a victim, causes Chrome's ServiceWorker implementation to incorrectly enforce Content Security Policy directives, allowing the policy to be circumvented. Exploitation requires user interaction (visiting a crafted page) but no authentication or elevated privileges. The Chromium issue tracker reference is bug #485785246, though full technical details remain restricted pending broad user adoption of the patch (Chrome Releases, GitHub Advisory).
Successful exploitation allows a remote attacker to bypass Content Security Policy protections enforced by the browser, which could enable injection of unauthorized scripts, loading of restricted resources, or other actions that CSP is designed to prevent. The integrity impact is rated Low, with no direct confidentiality or availability impact. While the vulnerability is limited in scope on its own, CSP bypass can serve as a stepping stone to facilitate cross-site scripting (XSS) or data exfiltration in web applications that rely on CSP as a primary defense layer (GitHub Advisory, Chrome Releases).
Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac). Users and organizations should update Google Chrome to version 147.0.7727.55 or later immediately, and ensure automatic updates are enabled to receive future security patches promptly. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. No configuration-based workaround is available; patching is the only remediation (Chrome Releases, Microsoft MSRC).
The Chrome 147 release was covered by security news outlets including GBHackers, which highlighted the broader update patching 60 vulnerabilities including two critical WebML flaws. The vulnerability itself, rated Low severity by Chromium, did not generate significant standalone commentary. Linux distribution security teams (Debian, openSUSE, FreeBSD) issued advisories and updated their Chromium packages in the days following the release (Chrome Releases).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."