Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-5894

Опубликовано: 08 апр. 2026
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

A flaw was found in the PDF component of Google Chrome and Chromium. A remote attacker could exploit this vulnerability by tricking a user into opening a specially crafted HTML page. This could allow the attacker to bypass navigation restrictions, potentially leading to unintended actions or access within the browser.

Отчет

Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-346
https://bugzilla.redhat.com/show_bug.cgi?id=2456807chromium-browser: Google Chrome/Chromium: Navigation restriction bypass via crafted HTML page

EPSS

Процентиль: 6%
0.00159
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.3
ubuntu
4 месяца назад

Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

CVSS3: 4.3
nvd
4 месяца назад

Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

msrc
4 месяца назад

Chromium: CVE-2026-5894 Inappropriate implementation in PDF

CVSS3: 4.3
debian
4 месяца назад

Inappropriate implementation in PDF in Google Chrome prior to 147.0.77 ...

CVSS3: 4.3
github
4 месяца назад

Inappropriate implementation in PDF in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

EPSS

Процентиль: 6%
0.00159
Низкий

5.4 Medium

CVSS3