CVE-2026-5899
Severity
6.1MEDIUM
No vectorEPSS
0.1%
top 82.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 8
Latest updateApr 9
Description
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Affected Packages1 packages
🔴Vulnerability Details
3GHSA▶
GHSA-7xx9-pp7c-pv8h: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147↗2026-04-09
CVEList▶
CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147↗2026-04-08
OSV▶
CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147↗2026-04-08