CVE-2026-5918
vulnerability analysis and mitigation

Overview

CVE-2026-5918 is a low-severity vulnerability involving an inappropriate implementation in the Navigation component of Google Chrome. It affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). The flaw was reported by Google on 2026-03-05 and patched with the Chrome 147 stable channel release on April 7, 2026. It carries a CVSS v3.1 base score of 4.3 (Medium) (Chrome Releases, GitHub Advisory).

Technical details

The vulnerability is classified under CWE-346 (Origin Validation Error) and CWE-352 (Cross-Site Request Forgery), stemming from an improper implementation in Chrome's Navigation subsystem that fails to correctly validate the origin of data or communications. Exploitation requires that an attacker has already compromised the renderer process; from that position, they can craft a malicious HTML page to leak cross-origin data that should be protected by the browser's same-origin policy. The Chromium issue tracker references bug ID 490139441 for this vulnerability (Chrome Releases, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker who has already compromised the renderer process to leak cross-origin data via a crafted HTML page, resulting in a low confidentiality impact with no integrity or availability impact. This could expose sensitive information from other origins that would normally be protected by the browser's same-origin policy, potentially enabling session data or credential leakage across sites. The scope of impact is limited to the browser context and does not directly enable code execution or system-level compromise (GitHub Advisory, Chrome Releases).

Mitigation and workarounds

Google has addressed this vulnerability in Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac), released on April 7, 2026. Microsoft has also issued a corresponding update for Edge (Chromium-based). Organizations should update all Chrome and Edge installations to the patched versions as soon as possible. No configuration-based workarounds are available; updating to the fixed version is the only recommended remediation (Chrome Releases, Microsoft MSRC).

Community reactions

Coverage of CVE-2026-5918 has been largely aggregated alongside the broader Chrome 147 security update, which addressed over 60 vulnerabilities including two critical WebML flaws. Security news outlets such as GBHackers and BeyondMachines covered the Chrome 147 release with emphasis on the higher-severity issues; CVE-2026-5918 received minimal individual attention given its low severity rating. Vulnerability tracking platforms including VulnDB, Tenable, and INCIBE catalogued the CVE shortly after disclosure (Chrome Releases).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management