Junglewise Threat Intelligence

CVE-2026-5905: Google Chrome domain spoofing in Permissions UI

CVE-2026-5905 · Severity: medium · CVSS 6.5 · Published 2026-04-08

Technologies: Microsoft Windows, Google Chrome. Vendors: Microsoft, Google.

Executive brief

A security issue in Google Chrome for Windows could allow a malicious website to misrepresent its identity. By tricking the browser's permission interface, an attacker could perform domain spoofing, potentially leading users to believe they are interacting with a trusted site when they are not. This could be used to facilitate phishing attacks or unauthorized data entry.

Technical details

A vulnerability classified as User Interface (UI) Misrepresentation of Critical Information (CWE-451) exists in the Permissions component of Google Chrome on Windows. The flaw stems from an incorrect security UI implementation that allows a remote attacker to perform domain spoofing. To exploit the vulnerability, an attacker must entice a user to visit a specially crafted HTML page. Successful exploitation allows the attacker to misrepresent the domain associated with browser permissions, potentially bypassing user-level security checks or facilitating phishing. The issue is resolved in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-12: disclosed: Reported by daffainfo
  • 2026-04-07: patched: Fixed in Chrome 147.0.7727.55 release
  • 2026-04-08: advisory: NVD publication date

References

Related threats