Description
Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: 4.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Policy bypass allowing unauthorized multi-downloads
Action: Patch
AI Analysis

Impact

The vulnerability is a policy bypass in the download manager of Google Chrome prior to version 147.0.7727.55. A crafted HTML page can cause the browser to ignore the multi‑download protection that normally limits the number of simultaneous downloads. This could let an attacker trigger multiple downloads without user consent, potentially consuming bandwidth, violating privacy, or enabling other secondary attacks. The weakness is related to failures to enforce download policy (CWE‑693) and improper handling of untrusted content (CWE‑807).

Affected Systems

Google Chrome browsers on Windows, macOS, and Linux that are older than version 147.0.7727.55 are affected. The issue applies to all platforms where Chrome is installed, as the policy enforcement flaw resides in the core download logic rather than operating‑system specific code.

Risk and Exploitability

The CVSS score of 4.3 indicates a low severity, and the EPSS score of less than 1% suggests a very low probability that the vulnerability is actively exploited in the wild. The vulnerability is not listed in CISA’s KEV catalog. Exploitation requires a remote attacker to host a specially crafted HTML page and to convince a user to load the page, implying the attack vector is likely user‑initiated phishing or social engineering. Given the low impact and limited exploitability, the risk to most organizations is modest, but it remains a security consideration for environments that enforce strict download policies.

Generated by OpenCVE AI on April 13, 2026 at 22:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Google Chrome to version 147.0.7727.55 or later
  • Verify that Chrome is set to the latest stable release and consider deploying group policy updates to enforce download limits

Generated by OpenCVE AI on April 13, 2026 at 22:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Debian DSA Debian DSA DSA-6205-1 chromium security update
History

Mon, 13 Apr 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows
CPEs cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Linux
Linux linux Kernel
Microsoft
Microsoft windows

Mon, 13 Apr 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-693
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 13 Apr 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-285

Fri, 10 Apr 2026 12:15:00 +0000

Type Values Removed Values Added
Title Chrome Multi-Download Protection Bypass via Crafted HTML Page chromium-browser: Policy bypass in Downloads
Weaknesses CWE-807
References
Metrics threat_severity

None

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

threat_severity

Low


Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Chrome Multi-Download Protection Bypass via Crafted HTML Page
First Time appeared Google
Google chrome
Weaknesses CWE-284
CWE-285
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Policy bypass in Downloads in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass of multi-download protections via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-13T18:17:35.740Z

Reserved: 2026-04-08T19:34:42.921Z

Link: CVE-2026-5900

cve-icon Vulnrichment

Updated: 2026-04-13T18:03:06.915Z

cve-icon NVD

Status : Analyzed

Published: 2026-04-08T22:16:29.890

Modified: 2026-04-13T21:14:34.223

Link: CVE-2026-5900

cve-icon Redhat

Severity : Low

Publid Date: 2026-04-07T00:00:00Z

Links: CVE-2026-5900 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-04-14T16:37:29Z

Weaknesses