Description
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: User-Interface XSS via History Navigation in Chrome 147
Action: Update Chrome
AI Analysis

Impact

Chromium’s policy enforcement for History Navigation failed to guard against the injection of arbitrary scripts or HTML when a user performed specific UI gestures on a crafted web page. An attacker who successfully lures a user into such gestures could cause the browser to execute malicious code embedded in the page, leading to style or script collateral damage but not necessarily full system compromise. The vulnerability is considered a low‑severity UXSS, implying limited impact on confidentiality or integrity should the user remain within the same browser context.

Affected Systems

The flaw affects Google Chrome versions prior to 147.0.7727.55. All operating systems running these earlier Chrome releases are susceptible; newer releases include the bug fix and are unaffected.

Risk and Exploitability

The CVSS score is low and no EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog, indicating a modest risk to the wider community. Successful exploitation requires user engagement and explicit UI gestures, which are typically achieved through a social‑engineering front. Because the attacker must convince a user to interact with a specially crafted page, the likelihood of widescale automatic exploitation is low, but targeted phishing attacks could still achieve the necessary conditions.

Generated by OpenCVE AI on April 8, 2026 at 22:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Chrome update (≥147.0.7727.55).
  • Verify that your browser is current before visiting unknown or suspicious sites.
  • Avoid performing the specific history navigation gestures with untrusted pages when possible.

Generated by OpenCVE AI on April 8, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title UXSS via History Navigation in Chrome 147
First Time appeared Google
Google chrome
Weaknesses CWE-79
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:58.656Z

Reserved: 2026-04-08T19:34:42.721Z

Link: CVE-2026-5899

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:29.787

Modified: 2026-04-08T22:16:29.787

Link: CVE-2026-5899

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:19Z

Weaknesses