Junglewise Threat Intelligence

CVE-2026-5897: Google Chrome UI spoofing in Downloads

CVE-2026-5897 · Severity: medium · CVSS 4.3 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A vulnerability in the browser's download interface could allow a malicious website to trick users into performing unintended actions by misrepresenting security information. This could lead to a user unknowingly downloading or executing harmful files under the impression they are interacting with a legitimate security prompt.

Technical details

A UI spoofing vulnerability exists in the Downloads component of Google Chrome prior to version 147.0.7727.55. The flaw stems from an incorrect implementation of security UI elements, which can be manipulated by a remote attacker using a crafted HTML page. Exploitation requires the attacker to convince a user to perform specific UI gestures, such as clicking or dragging, which then allows the attacker to misrepresent critical security information. This is classified as CWE-451 (User Interface Misrepresentation of Critical Information). The issue has been addressed in Chrome version 147.0.7727.55 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2025-05-24: disclosed: Reported by Farras Givari
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 stable channel update
  • 2026-04-08: advisory

References

Related threats