Junglewise Threat Intelligence

CVE-2026-5899: Google Chrome UXSS in History Navigation

CVE-2026-5899 · Severity: medium · CVSS 6.1 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in how the browser handles page history navigation could allow a malicious website to run unauthorized scripts on other websites you visit. To be successful, an attacker must trick a user into performing specific interactions or gestures on a specially crafted web page, potentially leading to the theft of sensitive information or unauthorized actions on other sites.

Technical details

A Universal Cross-Site Scripting (UXSS) vulnerability exists in Google Chrome's History Navigation component due to insufficient policy enforcement. The flaw allows a remote attacker to bypass the Same-Origin Policy (SOP) by convincing a user to perform specific UI gestures on a malicious HTML page. If successful, the attacker can execute arbitrary JavaScript or inject HTML into the context of other web origins. This issue is tracked as CWE-346 (Origin Validation Error) and was addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-01-11: other: Reported to vendor
  • 2026-04-07: patched: Stable channel update released
  • 2026-04-08: disclosed: Initial NVD publication

References

Related threats