CVE-2026-5880 is an insufficient policy enforcement vulnerability in Google Chrome versions prior to 147.0.7727.55 that allows a remote attacker with a compromised renderer process to spoof the contents of the Omnibox (URL bar) through a crafted HTML page. This vulnerability affects the browser's user interface integrity and is classified as medium severity by Chromium developers. The vulnerability has a CVSS score of 4.3 (Medium) with a network attack vector, low complexity, and no privileges required, though user interaction is necessary. The impact is limited to integrity—an attacker could deceive users about the actual website they are visiting—with no confidentiality or availability implications. Exploitation status is minimal to non-existent at present. The vulnerability is not tracked in CISA's Known Exploited Vulnerabilities catalog, has not been added to any public hot list, and shows very low community attention based on EPSS scoring of 0.00026. No active exploitation campaigns or readily available exploit code have been reported.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.