Junglewise Threat Intelligence

CVE-2026-5894: Google Chrome navigation restriction bypass in PDF

CVE-2026-5894 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

A vulnerability in Google Chrome's PDF component could allow a malicious website to bypass security restrictions that normally control how the browser navigates between pages. If a user visits a specially crafted website, the attacker could force the browser to navigate in ways that violate intended security boundaries. This could potentially be used as part of a more complex attack to mislead users or interact with other web content unexpectedly.

Technical details

An inappropriate implementation vulnerability exists in the PDF component of Google Chrome (specifically PDFium). The flaw allows a remote attacker to bypass navigation restrictions by enticing a user to visit a specially crafted HTML page. This is classified as an improper implementation of a security check (CWE-358). An exploit could allow an attacker to trigger unauthorized navigation actions that should otherwise be restricted by the browser's security model. The vulnerability was addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-05: other: Reported by Povcfe of Tencent Security Xuanwu Lab
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
  • 2026-04-08: disclosed: Initial NVD publication

References

Related threats