Junglewise Threat Intelligence

CVE-2026-5878: Google Chrome UI spoofing in Blink

CVE-2026-5878 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome's Blink engine allowed a remote attacker to misrepresent or spoof parts of the browser's user interface. By tricking a user into visiting a specially crafted website, an attacker could display misleading security information or fake interface elements. This could be used to facilitate phishing attacks or deceive users into performing unintended actions by making malicious content appear as legitimate browser notifications or security status indicators.

Technical details

A UI spoofing vulnerability exists in the Blink rendering engine of Google Chrome prior to version 147.0.7727.55. The flaw stems from an incorrect implementation of security UI elements, which can be manipulated by a remote attacker through a crafted HTML page. Exploitation requires a user to navigate to a malicious URL (User Interaction required). Successful exploitation allows the attacker to misrepresent critical security information or spoof browser UI components, potentially leading to effective phishing or social engineering attacks. The issue is tracked as CWE-451 and has been addressed in the Chrome 147 stable channel update.

Affected products

  • Google Chrome Prior to 147.0.7727.55

Timeline

  • 2024-09-06: other: Vulnerability reported to Chromium project
  • 2026-04-07: patched: Fixed in Chrome version 147.0.7727.55
  • 2026-04-08: disclosed: Public advisory published

References

Related threats