CVE-2026-5918Disclosure(apple / chrome)

LOWCVSS 4.3 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inappropriate implementation in Navigation in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-352

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • chrome
  • linux_kernel
  • macos
  • windows

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-02-19); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Products
chromelinux_kernelmacoswindows

1 version affected across 4 products

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-02-19: 1Mentions · 2026-04-09: 1Mentions · 2026-04-14: 1Technical Details · 2026-02-19: 1Technical Details · 2026-04-09: 102-1904-0904-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-04-091
Disclosure1
2026-04-141
General1
Full discourse3 posts
  • Aakash Rahsi@rahsi_aaka
    General

    CVE-2026-5918 | Chromium: CVE-2026-5918 Inappropriate implementation in Navigation https://www.aakashrahsi.online/post/cve-2026-5918 https://t.co/E0OuoTVaNC

    Post summary

    The tweet simply names CVE-2026-5918 for Chromium’s navigation component and links to a blog post, but offers no concrete technical details, PoC, or information on exploitation or mitigation.

    0000024
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-5918 Cross-Origin Data Leak in Google Chrome Prior to 147.0.7727.55 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-5918

    Post summary

    The post announces CVE-2026-5918 as a cross‑origin data leak impacting Chrome versions earlier than 147.0.7727.55, with no further technical, exploit, or patch details.

    0000074
    4.0K followersView on X
  • TermsofSurrender 🇨🇿 🇮🇱@Aftershockindex
    Disclosure

    🚨 Treeverse LakeFS Proves Your Fancy Git-Like Object Storage Is Just a Digital Sieve for Incompetence CVE-2026-5918 reveals a vulnerability in the lakeFS local block adapter before version 1.77.0 that compromises object storage integrity. It essentially turns your secure data lake into a public swimming pool for any threat actor with basic curiosity. While the GrayZone operatives are actually doing their jobs and highlighting this disaster, the Czech media is busy taking its third collective nap of the morning. It is absolutely pathetic that a critical vulnerability in core data infrastructure is being dissected globally while local newsrooms are still trying to figure out if they can report on it without a signed and notarized fax from the ministry. This lakeFS mess is exactly what happens when developers try to get cute with object storage, creating a 'Git-like' experience that includes Git-like security—which is to say, none at all if you leave the door unlatched. Prague’s bureaucratic machinery would probably try to fix this by putting a physical stamp on the server rack, completely oblivious to the fact that their data is currently being drained faster than a cheap pilsner at a tourist trap. You’re all sitting on a ticking time bomb, and your only defense is a system that moves slower than a tram during a snowstorm. PANIC: 82/100 | LAG: 0.21h | TRUST: 75% | ZONE: GrayZone https://hodl.cz/as-106163 #CyberSecurity #AfterShockIndex #CyberThreat #Cybersecurity #Czechia

    Post summary

    The text announces CVE-2026-5918, describing a storage‑integrity vulnerability in lakeFS before version 1.77.0, but offers no evidence of exploitation, PoC, patch, or false‑positive claims.

    0000033
    2 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSapplemacos---
Appgooglechrome---
OSlinuxlinux_kernel---
OSmicrosoftwindows---

Explore more