CVE-2026-5876 is a side-channel information leakage vulnerability in the Navigation feature of Google Chrome versions prior to 147.0.7727.55. This vulnerability allows remote attackers to leak cross-origin data through a specially crafted HTML page, potentially exposing sensitive information from other websites accessed by the user. The vulnerability carries a CVSS score of 6.5 (Medium severity) and requires minimal attack complexity, with exploitation triggered through user interaction with a malicious webpage. The attack has a network-based vector with no privilege requirements, and while the confidentiality impact is rated high, there is no impact to integrity or availability. The Chromium security team also classified this as medium severity. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.0003 indicating very low real-world exploitation probability. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog, and community attention appears limited based on its inactive status on threat tracking lists. However, organizations running Chrome versions prior to 147.0.7727.55 should prioritize patching given the cross-origin data leakage risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.