Junglewise Threat Intelligence

CVE-2026-5865: Google Chrome type confusion in V8

CVE-2026-5865 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Google Chrome. Vendors: Google.

Executive brief

Google Chrome is a widely used web browser. A security vulnerability in its V8 JavaScript engine could allow a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could still lead to unauthorized actions or serve as a stepping stone for further system compromise.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw is triggered when the engine incorrectly interprets the type of a resource, leading to memory corruption. A remote, unauthenticated attacker can exploit this by enticing a user to visit a malicious HTML page. Successful exploitation allows for arbitrary code execution within the Chromium sandbox. The vulnerability is addressed in Chrome version 147.0.7727.55 for Windows, Mac, and Linux.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-03-12: disclosed: Reported by Project WhatForLunch (@pjwhatforlunch)
  • 2026-04-07: patched: Chrome 147.0.7727.55 released to stable channel
  • 2026-04-08: advisory: NVD publication date

References