Junglewise Threat Intelligence

CVE-2026-5862: Google Chrome V8 inappropriate implementation code execution

CVE-2026-5862 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser for accessing the internet. A security vulnerability was identified in its V8 engine, which is responsible for processing JavaScript code. If a user visits a specially crafted, malicious website, an attacker could execute unauthorized code on the user's computer within the browser's security sandbox, potentially leading to further system compromise or data theft.

Technical details

A vulnerability classified as an 'inappropriate implementation' exists in the V8 JavaScript engine of Google Chrome. The flaw allows a remote, unauthenticated attacker to achieve arbitrary code execution within the browser's sandbox environment. Exploitation requires a user to navigate to a malicious web page (User Interaction). While the code execution is initially restricted to the sandbox, such vulnerabilities are frequently used as a primary stage in exploit chains to compromise the underlying host. The issue is resolved in Chrome version 147.0.7727.55 and later.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2025-12-21: disclosed: Reported to Chrome by Google internal researchers
  • 2026-04-07: patched: Stable channel update released for desktop
  • 2026-04-08: advisory: NVD publication date

References

Related threats