Domain Spoofing Vulnerability in Google Chrome for Windows
CVE-2026-5905

Currently unrated

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 April 2026

What is CVE-2026-5905?

A security flaw exists in the Permissions system of Google Chrome on Windows that can allow an attacker to exploit domain spoofing. By crafting a malicious HTML page, an attacker could mislead users by disguising the domain displayed in the browser’s security UI. This vulnerability poses a risk to user trust and the integrity of web browsing, underscoring the importance of keeping Chrome updated for safe browsing practices.

Affected Version(s)

Chrome 147.0.7727.55

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.