CVE-2026-5895
published 2026-04-08CVE-2026-5895: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a…
PriorityP426medium5.4CVSS 3.1
AVNACLPRNUIRSUCLINAL
EPSS
0.16%
5.4th percentile
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.15.4MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
osv5.4MEDIUM
vendor_redhat6.9MEDIUM
vendor_debian5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x449-4qch-5wjq: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5895 GHSA-x449-4qch-5wjq: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
OSV
CVE-2026-5895: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147
osv·2026-04-08·CVSS 5.4
CVE-2026-5895 [MEDIUM] CVE-2026-5895: Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
GHSA
Vert.x Web static handler component cache can be manipulated to deny the access to static files
ghsa·2026-01-15
CVE-2026-1002 [MEDIUM] CWE-444 Vert.x Web static handler component cache can be manipulated to deny the access to static files
Vert.x Web static handler component cache can be manipulated to deny the access to static files
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI.
The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used by Vert.x Web): https://github.com/eclipse-vertx/vert.x/pull/5895
Steps to reproduce
Given a file served by the static handler, craft an URI that introduces a string like bar%2F..%2F after the last / char to deny the access to the URI with an HTTP 404 response. For example https://example.com/foo/index.html can be denied with https://example.com/foo/bar%2F..%2Findex.html
Mitgation
Disabling Static
Red Hat
chromium-browser: Incorrect security UI in Omnibox
vendor_redhat·2026-04-07·CVSS 5.4
CVE-2026-5895 [MEDIUM] chromium-browser: Incorrect security UI in Omnibox
chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=374285495
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-5894
vendor_chrome·2026-04-07·CVSS 5.4
CVE-2026-5894 [LOW] Stable Channel Update for Desktop: CVE-2026-5894
Stable Channel Update for Desktop
CVE-2026-5894: Inappropriate implementation in PDF. Reported by Povcfe of Tencent Security Xuanwu Lab on 2026-02-05 [TBD][ 374285495 ] Low CVE-2026-5895: Incorrect security UI in Omnibox
Reported by Renwa Hiwa @RenwaX23 on 2024-10-18 [TBD][ 40064543 ] Low CVE-2026-5896: Policy bypass in Audio
Severity: low
Red Hat
io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
vendor_redhat·2026-01-15·CVSS 6.9
CVE-2026-1002 [MEDIUM] CWE-444 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI.
The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used by Vert.x Web): https://github.com/eclipse-vertx/vert.x/pull/5895
Steps to reproduce
Given a file served by the static handler, craft an URI that introduces a string like bar%2F..%2F after the last / char to deny the access to the URI with an HTTP 404 response. For example https://example.com/foo/index.html can be denied with https://example.com/foo/bar%2F..%2Findex.html
Mitgation
Disabling St
Debian
CVE-2026-5895: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 ...
vendor_debian·2026·CVSS 5.4
CVE-2026-5895 [MEDIUM] CVE-2026-5895: chromium - Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 ...
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-5895 chromium-browser: Incorrect security UI in Omnibox
bugzilla·2026-04-10·CVSS 5.4
CVE-2026-5895 [MEDIUM] CVE-2026-5895 chromium-browser: Incorrect security UI in Omnibox
CVE-2026-5895 chromium-browser: Incorrect security UI in Omnibox
An incorrect security ui flaw was found in the Omnibox component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=374285495
Bugzilla
CVE-2026-1002 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
bugzilla·2026-01-15·CVSS 6.9
CVE-2026-1002 [MEDIUM] CVE-2026-1002 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
CVE-2026-1002 io.vertx/vertx-core: static handler component cache can be manipulated to deny the access to static files
The Vert.x Web static handler component cache can be manipulated to deny the access to static files served by the handler using specifically crafted request URI.
The issue comes from an improper implementation of the C. rule of section 5.2.4 of RFC3986 and is fixed in Vert.x Core component (used by Vert.x Web): https://github.com/eclipse-vertx/vert.x/pull/5895
Steps to reproduce
Given a file served by the static handler, craft an URI that introduces a string like bar%2F..%2F after the last / char to deny the access to the URI with an HTTP 404 response. For example https://example.com/foo/index.html can be denied with https://example.com/foo/bar%2F..%2Findex.html
Mit
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5895 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5895 [HIGH] CVE-2026-5895 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5895 :
Google Chrome vulnerability analysis and mitigation
Incorrect security UI in Omnibox in Google Chrome on iOS prior to 147.0.7727.55 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted domain name. (Chromium security severity: Low)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 10.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix A
2026-04-08
Published