Type Confusion Vulnerability in Google Chrome
CVE-2026-5865

8.8HIGH

Key Information:

Vendor

Google

Status
Vendor
CVE Published:
8 April 2026

Badges

πŸ”₯ Trending nowπŸ“ˆ TrendedπŸ“ˆ Score: 1,540

What is CVE-2026-5865?

CVE-2026-5865 is a high-severity type confusion vulnerability found in the V8 JavaScript engine used by Google Chrome. This flaw enables a remote attacker to execute arbitrary code within the Chrome sandbox by leveraging specially crafted HTML content. If successfully exploited, this vulnerability could lead to significant security breaches, enabling attackers to bypass safeguards typically in place within the browser. The nature of the vulnerability lies in the way V8 handles certain types, which can cause confusion and result in unintended behaviors, subsequently jeopardizing the integrity of the affected systems.

Potential impact of CVE-2026-5865

  1. Remote Code Execution: The most critical impact of this vulnerability is the potential for remote code execution, allowing attackers to run malicious scripts within the browser. This can lead to unauthorized actions taken on behalf of the user, potentially compromising sensitive information.

  2. Sandbox Escape: Given that the vulnerability allows for execution within the Chrome sandbox, an attacker could utilize it to escape from this restricted environment, escalating access and manipulating the host system.

  3. Data Breaches and Information Theft: Exploitation of this vulnerability can result in unauthorized access to user data, leading to possible data breaches. This could involve theft of personal information, credentials, and other sensitive data, affecting individuals and organizations alike.

Affected Version(s)

Chrome 147.0.7727.55

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • πŸ“ˆ

    Vulnerability started trending

  • Vulnerability published

  • Vulnerability Reserved

.