CVE-2026-5876
published 2026-04-08CVE-2026-5876: Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML…
PriorityP432medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
EPSS
0.25%
16.1th percentile
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — | |
| paloalto | prisma_browser | — | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
osv6.5MEDIUM
vendor_debian6.5MEDIUM
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Google Chrome up to 146.0.7680.178 Navigation improper protection of physical side channels (ID 414852 / WID-SEC-2026-1030)
vuldb·2026-04-11·CVSS 6.5
CVE-2026-5876 [MEDIUM] Google Chrome up to 146.0.7680.178 Navigation improper protection of physical side channels (ID 414852 / WID-SEC-2026-1030)
A vulnerability labeled as problematic has been found in Google Chrome. Affected by this vulnerability is an unknown functionality of the component Navigation. Executing a manipulation can lead to improper protection of physical side channels.
This vulnerability is tracked as CVE-2026-5876. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-9wcm-fcg4-668c: Side-channel information leakage in Navigation in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5876 CWE-1300 GHSA-9wcm-fcg4-668c: Side-channel information leakage in Navigation in Google Chrome prior to 147
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2026-5876: Side-channel information leakage in Navigation in Google Chrome prior to 147
osv·2026-04-08·CVSS 6.5
CVE-2026-5876 [MEDIUM] CVE-2026-5876: Side-channel information leakage in Navigation in Google Chrome prior to 147
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Palo Alto
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
vendor_paloalto·2026-05-13·CVSS 8.8
CVE-2026-4439 [HIGH] PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
PAN-SA-2026-0007 Chromium and Prisma Browser: Monthly Vulnerability Update (May 2026)
Palo Alto Networks incorporated the following Chromium security fixes into our products: https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_28.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_22.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop_15.html https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html CVE Summary CVE-2026-4439 Out of bounds memory access in WebGL CVE-2026-4440 Out of bounds read and write in WebGL CVE-2026-4441 Use after free in Base CVE-2026-4442 Heap buffer overflow in
Chrome
Stable Channel Update for Desktop: CVE-2026-5876
vendor_chrome·2026-04-07·CVSS 6.5
CVE-2026-5876 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-5876
Stable Channel Update for Desktop
CVE-2026-5876: Side-channel information leakage in Navigation. Reported by Lyra Rebane (rebane2001) on 2023-12-18 [TBD][ 333024273 ] Medium CVE-2026-5877: Use after free in Navigation
Reported by Cassidy Kim(@cassidy6564) on 2024-04-05 [TBD][ 365089001 ] Medium CVE-2026-5878: Incorrect security UI in Blink
Severity: medium
Red Hat
chromium-browser: Side-channel information leakage in Navigation
vendor_redhat·2026-04-07·CVSS 6.5
CVE-2026-5876 [MEDIUM] CWE-346 chromium-browser: Side-channel information leakage in Navigation
chromium-browser: Side-channel information leakage in Navigation
A side-channel information leakage flaw was found in the Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=41485206
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2026-5876: chromium - Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7...
vendor_debian·2026·CVSS 6.5
CVE-2026-5876 [MEDIUM] CVE-2026-5876: chromium - Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7...
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [epel-all]
bugzilla·2026-04-09·CVSS 8.8
CVE-2026-5858 [HIGH] CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [epel-all]
CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-952f3c3d9e (chromium-147.0.7727.55-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-952f3c3d9e
---
FEDORA-EPEL-2026-718899309a (chromium-147.0.7727.55-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-718899309a
---
FEDORA-EPEL-2026-82b8678fe1 (chromium-147.0.7727.55-1.e
Bugzilla
CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [fedora-all]
bugzilla·2026-04-09·CVSS 8.8
CVE-2026-5858 [HIGH] CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [fedora-all]
CVE-2026-5858 CVE-2026-5859 CVE-2026-5860 CVE-2026-5861 CVE-2026-5874 CVE-2026-5875 CVE-2026-5876 CVE-2026-5894 chromium: various flaws [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-718899309a (chromium-147.0.7727.55-1.el10_3) has been submitted as an update to Fedora EPEL 10.3.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-718899309a
---
FEDORA-EPEL-2026-4bb81189d7 (chromium-147.0.7727.55-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-4bb81189d7
---
FEDORA-2026-f0ab053633 (chromium-147.0.7
Bugzilla
CVE-2026-5876 chromium-browser: Side-channel information leakage in Navigation
bugzilla·2026-04-08·CVSS 6.5
CVE-2026-5876 [MEDIUM] CVE-2026-5876 chromium-browser: Side-channel information leakage in Navigation
CVE-2026-5876 chromium-browser: Side-channel information leakage in Navigation
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5876 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5876 [HIGH] CVE-2026-5876 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5876 :
Google Chrome vulnerability analysis and mitigation
Side-channel information leakage in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix Added at: Apr
2026-04-08
Published