Description
Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
Published: 2026-04-08
Score: n/a
EPSS: n/a
KEV: No
Impact: Domain Spoofing
Action: Patch
AI Analysis

Impact

The vulnerability comes from an incorrect security UI in the permissions handling of Google Chrome on Windows, allowing an attacker to craft a malicious HTML page that deceives users into believing they are viewing a legitimate domain. This flaw enables remote domain spoofing and corresponds to the CWE-613 class of information exposure through UI.

Affected Systems

Only Windows installations of Google Chrome prior to version 147.0.7727.55 are affected. Updating to the patched version corrects the UI logic and prevents spoofing.

Risk and Exploitability

Chromium rates the issue as low severity and no EPSS score is available, so the real‑world exploitation likelihood is uncertain. However, a remote attacker could deliver the crafted HTML to a user without additional privileges, enabling domain spoofing. The vulnerability is not listed in the CISA KEV catalog, suggesting no known public exploits at this time.

Generated by OpenCVE AI on April 8, 2026 at 22:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Chrome to version 147.0.7727.55 or newer.
  • Verify that the update has been installed on all Windows machines.
  • Optionally monitor Chrome release notes for future patches.

Generated by OpenCVE AI on April 8, 2026 at 22:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 09 Apr 2026 08:30:00 +0000

Type Values Removed Values Added
Title Domain Spoofing via Incorrect Permission UI in Google Chrome on Windows
First Time appeared Google
Google chrome
Weaknesses CWE-613
Vendors & Products Google
Google chrome

Wed, 08 Apr 2026 21:30:00 +0000

Type Values Removed Values Added
Description Incorrect security UI in Permissions in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Chrome

Published:

Updated: 2026-04-08T21:21:01.314Z

Reserved: 2026-04-08T19:34:44.127Z

Link: CVE-2026-5905

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-04-08T22:16:30.397

Modified: 2026-04-08T22:16:30.397

Link: CVE-2026-5905

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-09T08:26:13Z

Weaknesses