CVE-2026-5899
UXSS Vulnerability in Chrome History Navigation Prior to
Publication date: 2026-04-08
Last updated on: 2026-04-13
Assigner: Chrome
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| chrome | to 147.0.7727.55 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-346 | The product does not properly verify that the source of data or communication is valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an insufficient policy enforcement issue in the History Navigation feature of Google Chrome versions prior to 147.0.7727.55. It allows a remote attacker to inject arbitrary scripts or HTML (known as UXSS - Universal Cross-Site Scripting) by convincing a user to perform specific user interface gestures on a specially crafted HTML page.
How can this vulnerability impact me? :
The impact of this vulnerability is that an attacker could execute arbitrary scripts or HTML in the context of the victim's browser. This could lead to unauthorized actions, data theft, or manipulation of web content viewed by the user. However, the severity of this issue is considered low by Chromium security standards.