Junglewise Threat Intelligence

CVE-2026-5896: Google Chrome policy bypass in Audio

CVE-2026-5896 · Severity: medium · CVSS 6.1 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in the browser's audio component could allow a malicious website to bypass security restrictions that normally prevent unauthorized file downloads. To be successful, an attacker would need to trick a user into performing specific interactions or gestures on a specially crafted webpage.

Technical details

A policy bypass vulnerability exists in the Audio component of Google Chrome prior to version 147.0.7727.55. The flaw stems from insufficient enforcement of sandbox restrictions when processing audio-related tasks. A remote attacker can exploit this by hosting a malicious HTML page and inducing a user to perform specific UI gestures. Successful exploitation allows the attacker to bypass sandbox download restrictions, potentially leading to unauthorized file placement on the user's system. The issue is addressed in the Chrome 147 stable channel update.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2023-05-13: disclosed: Reported by Luan Herrera
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55
  • 2026-04-08: advisory: NVD publication date

References

Related threats