CVE-2026-5895 is an incorrect security UI vulnerability affecting Google Chrome on iOS versions prior to 147.0.7727.55, wherein a remote attacker could craft a malicious domain name to spoof the contents of the Omnibox (URL bar), potentially deceiving users about which website they are visiting. This vulnerability carries a CVSS score of 5.4 (MEDIUM severity) with a network-based attack vector requiring minimal complexity and user interaction, presenting a confidentiality and availability impact. The attack has a low Chromium security rating and is not currently listed on the CISA KEV catalog, indicating no evidence of active exploitation in the wild. With an EPSS score of 0.0007 and a FAUCET risk score of 32.0/100, this vulnerability poses a relatively low exploitation probability and community attention risk compared to the broader CVE landscape. Organizations should prioritize patching Chrome on iOS to version 147.0.7727.55 or later as part of routine updates, though immediate emergency remediation is not warranted given the inactive exploitation status and low attack complexity requirements.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.