CVE-2026-5875 is a policy bypass vulnerability in the Blink rendering engine affecting Google Chrome versions prior to 147.0.7727.55. The flaw enables remote attackers to perform UI spoofing attacks through specially crafted HTML pages, potentially deceiving users into performing unintended actions. This vulnerability has been assigned a Medium severity classification by Chromium security review. The attack requires minimal technical complexity, as it can be executed over the network without elevated privileges and only necessitates user interaction with a malicious webpage. The CVSS 3.1 score of 4.3 reflects a limited impact scope, with potential integrity compromise but no confidentiality or availability impact. The relatively low CVSS score indicates this is a UI-focused deception attack rather than a critical system compromise vector. There is currently no evidence of active exploitation in the wild, with the EPSS score of 0.000250000 indicating minimal real-world exploitation probability. The vulnerability is not tracked on the Known Exploited Vulnerabilities (KEV) catalog, and it remains inactive on threat intelligence hot lists. Organizations should prioritize patching to Chrome 147.0.7727.55 or later as part of routine security updates, though this does not require emergency remediation protocols.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.