OVERVIEW CVE-2026-5899 is an insufficient policy enforcement vulnerability in Google Chrome's History Navigation feature that affects versions prior to 147.0.7727.55. The flaw allows remote attackers to inject arbitrary scripts or HTML through a crafted webpage, resulting in a Universal Cross-Site Scripting (UXSS) attack that bypasses the same-origin policy. SEVERITY The vulnerability carries a CVSS v3.1 score of 6.1 (Medium severity) with a network-based attack vector requiring minimal complexity and user interaction. The attack is unauthenticated and has a changed scope, enabling attackers to compromise confidentiality and integrity. Google classified the underlying issue as Low severity from a Chromium perspective, though the CVSS assessment reflects the broader impact potential across multiple security domains. EXPLOITATION STATUS Current indicators suggest minimal active exploitation risk. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities catalog, and the EPSS score of 0.00015 indicates it ranks lower than approximately 99.97 percent of all CVEs in terms of exploitation likelihood. The vulnerability remains inactive on public threat tracking lists, with no readily available public exploit code identified in community sources at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.