PT-2026-31519 · Google · Google Chrome

Lebr0Nli

·

Published

2026-01-29

·

Updated

2026-04-12

·

CVE-2026-5901

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Google Chrome versions prior to 147.0.7727.55
Description A flaw exists in the Google Chrome DevTools web development toolkit's data protection mechanism. Successful exploitation could allow a remote attacker to bypass security restrictions by loading a malicious extension. This could occur if a user is convinced to install a malicious extension. Insufficient policy enforcement in DevTools allowed bypassing enterprise host restrictions for cookie modification via a crafted Chrome Extension.
Recommendations Update Google Chrome to version 147.0.7727.55 or later.

Fix

Protection Mechanism Failure

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2026-04937
CVE-2026-5901
OPENSUSE-SU-2026:10530-1
OPENSUSE-SU-2026:20575-1

Affected Products

Google Chrome