OVERVIEW CVE-2026-5891 is an insufficient policy enforcement vulnerability affecting the browser UI in Google Chrome versions prior to 147.0.7727.55. The flaw allows a remote attacker who has already compromised the renderer process to conduct UI spoofing attacks by crafting malicious HTML pages. SEVERITY The vulnerability carries a CVSS score of 4.3 (Medium severity) with a network-based attack vector requiring user interaction. While attack complexity is low, the impact is limited to availability, with no confidentiality or integrity compromise. Chromium has classified this as medium severity, reflecting the need for a pre-compromised renderer process as a prerequisite condition. EXPLOITATION STATUS There is no evidence of active exploitation, with no CVE entry in the Known Exploited Vulnerabilities (KEV) catalog and an EPSS score of 0.000540, indicating very low real-world exploitation probability. No public exploit code is currently available, and community attention remains minimal. The vulnerability should be addressed through standard patching procedures, but poses limited immediate risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.