Description
Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: UI Spoofing, Potential Phishing
Action: Patch Update
AI Analysis

Impact

The vulnerability arises from insufficient policy enforcement in Google Chrome’s browser user interface. A remote attacker who has already compromised the renderer process can craft a malicious HTML page that mimics legitimate UI elements, enabling UI spoofing. The flaw is rated medium severity by Chromium security.

Affected Systems

Affected releases are the desktop versions of Google Chrome older than 147.0.7727.55. The issue is noted in the stable channel update for that version, and the references point to the official Chrome release notes.

Risk and Exploitability

Exploitation requires the renderer process to be compromised, a condition that already indicates a significant breach. With that prerequisite, the attacker can perform spoofing to deceive users into revealing sensitive information or executing unintended actions. Because the EPSS score is unavailable and the vulnerability is not listed in CISA’s KEV catalog, the overall exploitation probability is uncertain, but the medium severity suggests a moderate risk that warrants timely patching.

Generated by OpenCVE AI on April 8, 2026 at 22:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Google Chrome to version 147.0.7727.55 or later.

Generated by OpenCVE AI on April 8, 2026 at 22:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Insufficient UI Policy Enforcement Enables Renderer-Based Spoofing in Chrome
First Time appeared Google
Google chrome
Weaknesses CWE-1036
CWE-264
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in browser UI in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:53.739Z

Reserved: 2026-04-08T19:34:40.426Z

Link: CVE-2026-5891

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:28.990

Modified: 2026-04-08T22:16:28.990

Link: CVE-2026-5891

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:27Z

Weaknesses