Junglewise Threat Intelligence

CVE-2026-5881: Google Chrome policy bypass in LocalNetworkAccess

CVE-2026-5881 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A security flaw in Google Chrome's LocalNetworkAccess component could allow a malicious website to bypass standard security restrictions. By tricking a user into visiting a specially crafted webpage, an attacker could potentially interact with or navigate to internal network resources that should otherwise be protected. This could lead to unauthorized actions on a user's private network or internal services.

Technical details

A policy bypass vulnerability exists in the LocalNetworkAccess (formerly Private Network Access) implementation in Google Chrome prior to version 147.0.7727.55. The flaw stems from improper access control (CWE-284) when handling navigation requests. A remote, unauthenticated attacker can exploit this by hosting a malicious HTML page and inducing a user to visit it. Successful exploitation allows the attacker to bypass security policies designed to restrict web pages from initiating unauthorized connections or navigations to the user's local network. This issue is resolved in version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2025-10-22: other: Vulnerability reported to Chromium project
  • 2026-04-07: patched: Stable channel update released for Desktop
  • 2026-04-08: disclosed: Initial CVE publication

References

Related threats