Junglewise Threat Intelligence

CVE-2026-5880: Google Chrome URL spoofing in browser UI

CVE-2026-5880 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A vulnerability in the browser's user interface could allow a malicious website to display a fake web address in the URL bar (Omnibox). This could be used in phishing attacks to trick users into believing they are on a legitimate site, such as a bank or email provider, when they are actually on a site controlled by an attacker.

Technical details

This vulnerability is classified as a User Interface (UI) Misrepresentation (CWE-451) due to insufficient policy enforcement in the browser's UI components. An attacker who has already compromised the renderer process can exploit this flaw by using a specially crafted HTML page to spoof the Omnibox (URL bar) content. This requires user interaction, typically in the form of visiting a malicious website. Successful exploitation allows the attacker to misrepresent the origin of the page, facilitating sophisticated phishing or social engineering attacks. The issue is resolved in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome Prior to 147.0.7727.55

Timeline

  • 2025-06-14: other: Vulnerability reported to Chromium by anonymous researcher
  • 2026-04-07: patched: Fixed in Chrome Stable Channel Update 147.0.7727.55
  • 2026-04-08: disclosed: Public disclosure of CVE-2026-5880

References

Related threats