Junglewise Threat Intelligence

CVE-2026-5901: Google Chrome policy bypass in DevTools

CVE-2026-5901 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its developer tools (DevTools) could allow a malicious browser extension to bypass security restrictions set by an organization. Specifically, an attacker who tricks a user into installing a malicious extension could modify browser cookies on websites that should be protected by enterprise security policies.

Technical details

A policy bypass vulnerability exists in the DevTools component of Google Chrome due to insufficient policy enforcement. An attacker can exploit this by convincing a user to install a specially crafted Chrome Extension. Once installed, the extension can bypass enterprise host restrictions to modify cookies on domains that are otherwise protected by administrative policies. This issue is categorized as CWE-602 (Client-Side Enforcement of Server-Side Security). The vulnerability is addressed in Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-01-29: disclosed: Reported by Povcfe of Tencent Security Xuanwu Lab
  • 2026-04-07: patched: Fixed in Chrome 147 stable channel release
  • 2026-04-08: advisory

References

Related threats