CVE-2026-5896 is a policy bypass vulnerability in the Audio component of Google Chrome versions prior to 147.0.7727.55. The flaw allows a remote attacker to circumvent sandbox download restrictions by convincing a user to perform specific UI gestures on a maliciously crafted HTML page. Google classified this as a Low-severity issue within Chromium. The vulnerability carries a CVSS score of 6.1 (Medium), indicating moderate risk with network-based attack vectors requiring low complexity and user interaction. The attack has cross-site scope, potentially affecting system confidentiality and integrity while maintaining availability. The low EPSS score of 0.0003 suggests minimal exploitation prevalence in the wild relative to other disclosed vulnerabilities. There is no evidence of active exploitation in the wild, with no known exploit code publicly available and the vulnerability remaining inactive on exploit tracking lists. Community attention appears limited given the low severity classification and lack of inclusion in the Known Exploited Vulnerabilities catalog. Organizations should prioritize patching based on standard update schedules rather than treating this as an emergency-level threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.