CVE-2026-5878
published 2026-04-08CVE-2026-5878: Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium…
PriorityP419medium4.3CVSS 3.1
AVNACLPRNUIRSUCNILAN
EPSS
0.19%
9.0th percentile
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.14.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
osv4.3MEDIUM
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5878
vendor_chrome·2026-04-22·CVSS 4.3
CVE-2026-5878 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5878
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-5878
Red Hat
chromium-browser: Incorrect security UI in Blink
vendor_redhat·2026-04-07·CVSS 4.3
CVE-2026-5878 [MEDIUM] CWE-1021 chromium-browser: Incorrect security UI in Blink
chromium-browser: Incorrect security UI in Blink
An incorrect security ui flaw was found in the Blink component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=365089001
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-5876
vendor_chrome·2026-04-07·CVSS 6.5
CVE-2026-5876 [MEDIUM] Stable Channel Update for Desktop: CVE-2026-5876
Stable Channel Update for Desktop
CVE-2026-5876: Side-channel information leakage in Navigation. Reported by Lyra Rebane (rebane2001) on 2023-12-18 [TBD][ 333024273 ] Medium CVE-2026-5877: Use after free in Navigation
Reported by Cassidy Kim(@cassidy6564) on 2024-04-05 [TBD][ 365089001 ] Medium CVE-2026-5878: Incorrect security UI in Blink
Severity: medium
Debian
CVE-2026-5878: chromium - Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a...
vendor_debian·2026·CVSS 4.3
CVE-2026-5878 [MEDIUM] CVE-2026-5878: chromium - Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a...
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
VulDB
Google Chrome up to 146.0.7680.178 Blink ui layer (ID 365089 / WID-SEC-2026-1030)
vuldb·2026-04-11·CVSS 4.3
CVE-2026-5878 [MEDIUM] Google Chrome up to 146.0.7680.178 Blink ui layer (ID 365089 / WID-SEC-2026-1030)
A vulnerability has been found in Google Chrome and classified as problematic. This affects an unknown part of the component Blink. Performing a manipulation results in improper restriction of rendered ui layers.
This vulnerability is reported as CVE-2026-5878. The attack is possible to be carried out remotely. No exploit exists.
The affected component should be upgraded.
GHSA
GHSA-gfjm-pp2m-j8cw: Incorrect security UI in Blink in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5878 GHSA-gfjm-pp2m-j8cw: Incorrect security UI in Blink in Google Chrome prior to 147
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
OSV
CVE-2026-5878: Incorrect security UI in Blink in Google Chrome prior to 147
osv·2026-04-08·CVSS 4.3
CVE-2026-5878 [MEDIUM] CVE-2026-5878: Incorrect security UI in Blink in Google Chrome prior to 147
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
No detection rules found.
No public exploits indexed.
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5878 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5878 [HIGH] CVE-2026-5878 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5878 :
Google Chrome vulnerability analysis and mitigation
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix Added at: Apr 09, 2026
## Get a
Bugzilla
CVE-2026-5878 chromium-browser: Incorrect security UI in Blink
bugzilla·2026-04-08·CVSS 4.3
CVE-2026-5878 [MEDIUM] CVE-2026-5878 chromium-browser: Incorrect security UI in Blink
CVE-2026-5878 chromium-browser: Incorrect security UI in Blink
Incorrect security UI in Blink in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Medium)
2026-04-08
Published