Junglewise Threat Intelligence

CVE-2026-5861: Google Chrome use after free in V8

CVE-2026-5861 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized access to data or further system compromise.

Technical details

A use-after-free (UAF) vulnerability exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine attempts to access memory that has already been freed, typically during the processing of malicious JavaScript within a crafted HTML page. A remote, unauthenticated attacker can exploit this by inducing a user to visit a malicious website, leading to arbitrary code execution within the context of the browser's sandbox. This vulnerability was addressed in Google Chrome version 147.0.7727.55.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-02-23: disclosed: Vulnerability reported to Chrome by researcher 5shain
  • 2026-04-07: patched: Chrome 147 stable channel update released
  • 2026-04-08: advisory: CVE published

References

Related threats