Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5899

24
FAUCET Score

OVERVIEW CVE-2026-5899 is an insufficient policy enforcement vulnerability in Google Chrome's History Navigation feature that affects versions prior to 147.0.7727.55. The flaw allows remote attackers to inject arbitrary scripts or HTML through a crafted webpage, resulting in a Universal Cross-Site Scripting (UXSS) attack that bypasses the same-origin policy. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.1 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction. The attack is unauthenticated and has a changed scope, enabling attackers to compromise confidentiality and integrity. Google classified the underlying issue as Low severity from a Chromium perspective, though the CVSS assessment reflects the broader impact potential across multiple security domains. EXPLOITATION STATUS Current indicators suggest minimal active exploitation risk. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00015 indicates it ranks lower than approximately 99.97 percent of all CVEs in terms of exploitation likelihood. The vulnerability remains inactive on public threat tracking lists, with no readily available public exploit code identified in community sources at this time.

Impacted Technologies

VendorProductVersion(s)CPE
< 147.0.7727.55CPE matchmatch criteria
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
>= 147.0.7727.55, < 147.0.7727.55CPE match
cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.1MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.8
Impact Score
2.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.13%
Probability of exploitation in next 30 days
EPSS Percentile
3.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0013 is in the 2nd percentile among its peer group of 26,236 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Microsoft Edge (Chromium-based)Fixed in: 147.0.3912.60
googlevendor investigatingvia chrome_releases
View patch

Vendor Advisories (2)

microsoft2026-Apr/CVE-2026-5899

Chromium: CVE-2026-5899 Incorrect security UI in History Navigation

Apr 2, 2026
googlegoogle:chrome-7d655429efb624cbCRITICAL

Stable Channel Update for ChromeOS / ChromeOS Flex

References

chromereleases.googleblog.com / 2026/04/stable-channel-update-for-desktop.html
Release NotesVendor Advisory
issues.chromium.org / issues/474817168
Issue TrackingPermissions Required