CVE-2026-5899
published 2026-04-08CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in…
PriorityP427medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.13%
3.3th percentile
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
osv6.1MEDIUM
vendor_debian6.1MEDIUM
vendor_redhat6.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7xx9-pp7c-pv8h: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5899 GHSA-7xx9-pp7c-pv8h: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
OSV
CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147
osv·2026-04-08·CVSS 6.1
CVE-2026-5899 [MEDIUM] CVE-2026-5899: Insufficient policy enforcement in History Navigation in Google Chrome prior to 147
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5899
vendor_chrome·2026-04-22·CVSS 6.1
CVE-2026-5899 [MEDIUM] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5899
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-5899
Red Hat
chromium-browser: Incorrect security UI in History Navigation
vendor_redhat·2026-04-07·CVSS 6.1
CVE-2026-5899 [MEDIUM] CWE-79 chromium-browser: Incorrect security UI in History Navigation
chromium-browser: Incorrect security UI in History Navigation
An incorrect security ui flaw was found in the History Navigation component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=474817168
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Chrome
Stable Channel Update for Desktop: CVE-2026-5897
vendor_chrome·2026-04-07·CVSS 4.3
CVE-2026-5897 [LOW] Stable Channel Update for Desktop: CVE-2026-5897
Stable Channel Update for Desktop
CVE-2026-5897: Incorrect security UI in Downloads. Reported by Farras Givari on 2025-05-24 [TBD][ 470295118 ] Low CVE-2026-5898: Incorrect security UI in Omnibox
Reported by saidinahikam032 on 2025-12-19 [TBD][ 474817168 ] Low CVE-2026-5899: Incorrect security UI in History Navigation
Severity: low
Debian
CVE-2026-5899: chromium - Insufficient policy enforcement in History Navigation in Google Chrome prior to ...
vendor_debian·2026·CVSS 6.1
CVE-2026-5899 [MEDIUM] CVE-2026-5899: chromium - Insufficient policy enforcement in History Navigation in Google Chrome prior to ...
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
No detection rules found.
No public exploits indexed.
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5899 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5899 [HIGH] CVE-2026-5899 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5899 :
Google Chrome vulnerability analysis and mitigation
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.3
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09
Bugzilla
CVE-2026-5899 chromium-browser: Incorrect security UI in History Navigation
bugzilla·2026-04-08·CVSS 6.1
CVE-2026-5899 [MEDIUM] CVE-2026-5899 chromium-browser: Incorrect security UI in History Navigation
CVE-2026-5899 chromium-browser: Incorrect security UI in History Navigation
Insufficient policy enforcement in History Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: Low)
Bugzilla
CVE-2025-5899 pspp: GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heap [fedora-42]
bugzilla·2025-06-10·CVSS 4.8
CVE-2025-5899 [MEDIUM] CVE-2025-5899 pspp: GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heap [fedora-42]
CVE-2025-5899 pspp: GNU PSPP pspp-convert.c parse_variables_option free of memory not on the heap [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2371321
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-e153173659 (pspp-2.1.1-5.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-e153173659
---
FEDORA-2026-7b2964fc42 (pspp-2.1.1-5.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7b2964fc42
---
FEDO
2026-04-08
Published