CVE-2026-5892 is an insufficient policy enforcement vulnerability affecting Google Chrome versions prior to 147.0.7727.55 that could allow a remote attacker with a compromised renderer process to install Progressive Web Applications (PWAs) without explicit user consent through a malicious HTML page. This vulnerability specifically undermines Chrome's PWA installation safeguards, potentially enabling unauthorized application deployment on affected systems. The vulnerability carries a Medium severity rating with a CVSS score of 6.6, requiring local access and user interaction but presenting high integrity and availability impacts. The attack vector is local with low complexity, meaning an attacker who has already compromised the renderer process can exploit it relatively easily through social engineering or other initial compromise methods. There is currently no evidence of active exploitation in the wild. The vulnerability does not appear on the Known Exploited Vulnerabilities (KEV) catalog, is inactive on threat intelligence hot lists, and maintains an exceptionally low EPSS score of 0.0003, indicating minimal probability of near-term exploitation. No public exploit code is known to be available, suggesting limited community attention or weaponization at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.