PatchSiren cyber security CVE debrief
CVE-2026-5887 Google CVE debrief
CVE-2026-5887 is a Medium severity vulnerability in Google Chrome on Windows, allowing a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as CWE-20. Affected product is Google Chrome on Windows prior to version 147.0.7727.55. Likely operational impact includes unauthorized downloads. Source confidence is high based on CVE.org and NVD details.
- Vendor
- Product
- Chrome
- CVSS
- MEDIUM 4.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Users of Google Chrome on Windows prior to version 147.0.7727.55 should apply the update to prevent potential bypass of download restrictions. Affected operators include Chrome administrators, security teams, and IT personnel responsible for Windows systems. Vulnerability management and security teams should review and implement compensating controls if immediate patching is not feasible.
Technical summary
Insufficient validation of untrusted input in Downloads in Google Chrome on Windows prior to 147.0.7727.55 allowed a remote attacker to bypass download restrictions via a crafted HTML page. The vulnerability has a CVSS score of 4.3 and is classified as CWE-20. Affected product deployments include Google Chrome on Windows environments. Defensive impact includes applying updates, verifying download restrictions, and monitoring for suspicious activity. Source confidence is high based on CVE.org and NVD details. Evidence is limited to publicly available details from CVE.org and NVD. Defenders should verify Chrome version 147.0.7727.55 or later is deployed, review download restrictions, and monitor for suspicious download activity.
Defensive priority
Medium priority, as the vulnerability allows bypass of download restrictions but does not allow arbitrary code execution or privilege escalation.
Recommended defensive actions
- Apply the update to Google Chrome on Windows to version 147.0.7727.55 or later
- Verify that Google Chrome is updated to the latest version
- Monitor for any suspicious activity related to downloads in Google Chrome
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD detail provide information on the vulnerability, its severity, and affected versions. The Chromium security severity is Medium. Evidence is limited to publicly available details from CVE.org and NVD. Defenders should verify Chrome version 147.0.7727.55 or later is deployed, review download restrictions, and monitor for suspicious download activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-5887 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-5887
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-5887 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-5887
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html
[email protected] - Release Notes, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://issues.chromium.org/issues/486079015
[email protected] - Issue Tracking, Permissions Required
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.