Description
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Download Bypass
Action: Patch Update
AI Analysis

Impact

A crafted HTML page can cause Google Chrome to automatically download multiple files without prompting the user, bypassing the browser’s built‑in multi‑download protection. This flaw allows an attacker to trigger the acquisition of arbitrary content, potentially including malware or other unwanted files, without the user’s explicit consent. The weakness arises from improper enforcement of download policies, effectively granting the attacker elevated permissions to initiate downloads.

Affected Systems

All desktop installations of Google Chrome with versions earlier than 147.0.7727.55 are affected. The issue is not limited to a specific operating system; any platform that runs Chrome in this vulnerable version range can be targeted.

Risk and Exploitability

Chromium classifies the severity of this issue as Low and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The likely attack vector is a malicious web page delivered over the network; an unsuspecting user who opens that page may trigger the automatic downloads. Because the flaw does not provide arbitrary code execution, the risk is moderate, yet it remains a vector for phishing and malware delivery when the user is unaware of the downloads.

Generated by OpenCVE AI on April 8, 2026 at 22:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 147.0.7727.55 or later.

Generated by OpenCVE AI on April 8, 2026 at 22:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome Multi-Download Protection Bypass via Crafted HTML Page
First Time appeared Google
Google chrome
Weaknesses CWE-284
CWE-285
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:20:59.034Z

Reserved: 2026-04-08T19:34:42.921Z

Link: CVE-2026-5900

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:29.890

Modified: 2026-04-08T22:16:29.890

Link: CVE-2026-5900

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:18Z

Weaknesses