CVE-2026-5892
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer p
CVSS
6.6
Medium
EPSS
0.2%
p7
KEV
—
Exploit Today
2
0-100
Published: Apr 8, 2026 · Last modified: Jul 24, 2026 · CWE-1268
0.2%EPSS · 30 days0.2%
2026-07-052026-08-02
Insufficient policy enforcement in PWAs in Google Chrome prior to 147.0.7727.55 allowed a remote attacker who had compromised the renderer process to install a PWA without user consent via a crafted HTML page. (Chromium security severity: Medium)
No related CVEs by CWE or product.