Junglewise Threat Intelligence

CVE-2026-5871: Google Chrome type confusion in V8

CVE-2026-5871 · Severity: high · CVSS 8.8 · Published 2026-04-08

Technologies: Apple macOS, Microsoft Windows, Google Chrome, Linux Kernel. Vendors: Apple, Microsoft, Google, Linux.

Executive brief

Google Chrome is a widely used web browser. A vulnerability in its V8 JavaScript engine allows a remote attacker to execute malicious code on a user's computer if they visit a specially crafted website. While the attack is limited by the browser's security sandbox, it could lead to unauthorized data access or further system compromise.

Technical details

A type confusion vulnerability (CWE-843) exists in the V8 JavaScript engine component of Google Chrome. The flaw occurs when the engine incorrectly processes objects of incompatible types, which can be triggered by a remote attacker through a specially crafted HTML page. Successful exploitation allows for remote code execution (RCE) within the context of the Chromium sandbox. The vulnerability is addressed in Google Chrome version 147.0.7727.55 for Windows, Mac, and Linux. Exploitation requires user interaction, specifically convincing a user to visit a malicious URL.

Affected products

  • Google Chrome prior to 147.0.7727.55

Timeline

  • 2026-03-24: disclosed: Reported to Chromium by Google internal researchers
  • 2026-04-07: patched: Fixed in Chrome stable channel update 147.0.7727.55
  • 2026-04-08: advisory: NVD publication date

References

Related threats