PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5887 Google CVE debrief

CVE-2026-5887 is a Medium severity vulnerability in Google Chrome on Windows, allowing a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as CWE-20. Affected product is Google Chrome on Windows prior to version 147.0.7727.55. Likely operational impact includes unauthorized downloads. Source confidence is high based on CVE.org and NVD details.

Vendor
Google
Product
Chrome
CVSS
MEDIUM 4.3
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-08
Original CVE updated
2026-07-24
Advisory published
2026-04-08
Advisory updated
2026-07-24

Who should care

Users of Google Chrome on Windows prior to version 147.0.7727.55 should apply the update to prevent potential bypass of download restrictions. Affected operators include Chrome administrators, security teams, and IT personnel responsible for Windows systems. Vulnerability management and security teams should review and implement compensating controls if immediate patching is not feasible.

Technical summary

Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as CWE-20. Affected product deployments include Google Chrome on Windows environments. Defensive impact includes applying updates, verifying download restrictions, and monitoring for suspicious activity. Source confidence is high based on CVE.org and NVD details. Evidence is limited to publicly available details from CVE.org and NVD. Defenders should verify Chrome version 147.0.7727.55 or later is deployed, review download restrictions, and monitor for suspicious download activity.

Defensive priority

Medium priority, as the vulnerability allows bypass of download restrictions but does not allow arbitrary code execution or privilege escalation.

Recommended defensive actions

  • Apply the update to Google Chrome on Windows to version 147.0.7727.55 or later
  • Verify that Google Chrome is updated to the latest version
  • Monitor for any suspicious activity related to downloads in Google Chrome
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD detail provide information on the vulnerability, its severity, and affected versions. The Chromium security severity is Medium. Evidence is limited to publicly available details from CVE.org and NVD. Defenders should verify Chrome version 147.0.7727.55 or later is deployed, review download restrictions, and monitor for suspicious download activity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-5887 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-5887

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-5887 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5887

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.