PT-2026-31510 · Google · Google Chrome

Tianyi Hu

·

Published

2026-02-25

·

Updated

2026-04-12

·

CVE-2026-5892

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:N
**Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.55
Description A flaw in policy enforcement within Progressive Web Apps (PWAs) in Google Chrome before version 147.0.7727.55 permitted a remote attacker, having already compromised the renderer process, to install a PWA without explicit user permission through a specially crafted HTML page.
Recommendations Update Google Chrome to version 147.0.7727.55 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2026-04988
CVE-2026-5892
OPENSUSE-SU-2026:10530-1
OPENSUSE-SU-2026:20575-1

Affected Products

Google Chrome