Description
Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Navigation Restriction Bypass
Action: Patch Immediately
AI Analysis

Impact

In Chrome versions prior to 147.0.7727.55, a flaw in PDF handling allows a remote attacker to craft an HTML page that forces the browser to navigate to an arbitrary URL while bypassing the browser’s navigation restrictions. The inappropriate implementation in the PDF component leads to a controlled redirect that does not honor the usual security checks. This can enable an attacker to direct a user to malicious sites, potentially facilitating phishing or other social engineering attacks. The vulnerability does not provide direct code execution and is classified with low severity by Chromium security. While the impact is limited, the fact that a crafted page can alter navigation flows could be leveraged in malicious campaigns.

Affected Systems

All installations of Google Chrome before release 147.0.7727.55 on desktop platforms are affected. The issue applies to all operating systems supported by the stable channel as it stems from the core PDF rendering engine shared across them.

Risk and Exploitability

The CVSS assessment rates this vulnerability as low and the EPSS score is not available, indicating a lower likelihood of widespread exploitation. The flaw can be triggered from any web page that the victim visits, requiring no local privileges or advanced setup. Attackers could embed the crafted page in a website or email to exploit the navigation bypass. Although not currently listed in the CISA KEV catalog, the risk is moderate due to the potential for phishing campaigns that rely on redirecting users to attacker-controlled domains.

Generated by OpenCVE AI on April 8, 2026 at 22:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to Chrome version 147.0.7727.55 or later using the stable channel,
  • Ensure that automatic updates are enabled on all machines to receive future patches promptly
  • If an update cannot be applied immediately, use enterprise policies or extensions to block or restrict navigation to untrusted domains
  • Monitor Chrome release notes and issue trackers for further mitigation recommendations

Generated by OpenCVE AI on April 8, 2026 at 22:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Remote Navigation Restriction Bypass via Crafted PDF in Chrome
First Time appeared Google
Google chrome
Weaknesses CWE-79
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:56.746Z

Reserved: 2026-04-08T19:34:41.121Z

Link: CVE-2026-5894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:29.290

Modified: 2026-04-08T22:16:29.290

Link: CVE-2026-5894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:24Z

Weaknesses