Description
Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Fullscreen UI Spoofing
Action: Update Browser
AI Analysis

Impact

A flaw in Chrome’s fullscreen rendering logic allowed a malicious web page to display a deceptive security interface when the browser was in fullscreen. The vulnerability does not grant code execution or data exfiltration; it simply lets a remote attacker craft a UI that mimics legitimate browser dialogs, potentially convincing a user to provide credentials or perform unintended actions.

Affected Systems

Google Chrome desktop releases older than 147.0.7727.55 on any supported operating system are affected. Users who browse the Internet with such versions should avoid allowing websites to request fullscreen, as the UI could be spoofed.

Risk and Exploitability

Chromium labels the issue a Medium severity, but no numeric CVSS score is supplied. EPSS data is unavailable and the vulnerability is not in the CISA KEV catalog. Attack requires a remote attacker to host a malicious page and a user to visit and enable fullscreen; the exploitation is limited to social‑engineering or phishing scenarios rather than arbitrary code execution.

Generated by OpenCVE AI on April 9, 2026 at 00:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 147.0.7727.55 or later

Generated by OpenCVE AI on April 9, 2026 at 00:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome Fullscreen UI Spoofing Vulnerability
First Time appeared Google
Google chrome
Weaknesses CWE-79
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Fullscreen in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:49.954Z

Reserved: 2026-04-08T19:34:37.957Z

Link: CVE-2026-5882

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:27.847

Modified: 2026-04-08T22:16:27.847

Link: CVE-2026-5882

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:44Z

Weaknesses