
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-4447 is a type confusion vulnerability (inappropriate implementation) in the V8 JavaScript engine in Google Chrome that allows a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. It was reported by researcher "Erge" on February 23, 2026, and publicly disclosed on March 18, 2026, when Google released Chrome 146.0.7680.153. Affected products include Google Chrome prior to version 146.0.7680.153 and Microsoft Edge (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release Blog, Red Hat Bugzilla, Microsoft MSRC).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / Type Confusion) within Chrome's V8 JavaScript engine, caused by an inappropriate implementation that fails to correctly enforce type constraints during JavaScript execution. An attacker can exploit this by serving a specially crafted HTML page that triggers the type confusion flaw in V8, leading to arbitrary code execution within the Chrome sandbox. Exploitation requires user interaction — specifically, a victim must visit or interact with a malicious web page — but no authentication or special privileges are needed on the attacker's side. The vulnerability was part of a broader Chrome update that addressed 26 security issues, including multiple other high-severity V8 flaws (Chrome Release Blog, Red Hat Bugzilla).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox, compromising confidentiality, integrity, and availability of the browser context. While the sandbox limits direct host OS access, code execution within the sandbox can serve as a stepping stone for sandbox escape chains, potentially leading to broader system compromise. Sensitive data accessible within the browser — including session tokens, credentials, and browsing history — is at risk of exposure (Chrome Release Blog, Red Hat Bugzilla).
cmd.exe, powershell.exe, bash, curl, wget); Chrome renderer processes exhibiting abnormal CPU or memory usage.Google has released Chrome 146.0.7680.153 (Linux) and 146.0.7680.153/154 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism (Chrome Release Blog). Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update referenced in the Microsoft Security Response Center advisory (Microsoft MSRC). As a temporary workaround for organizations unable to patch immediately, restrict user browsing to trusted sites, deploy web filtering/proxy controls to block access to untrusted or newly registered domains, and educate users to avoid clicking suspicious links. Linux distribution packages (Debian, Fedora, openSUSE) have also released updated Chromium packages addressing this CVE.
The vulnerability was covered by multiple cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, primarily in the context of the broader Chrome update that fixed 26 security flaws (GBHackers, CyberSecurityNews). SecurityOnline.info described the update as "urgent" given the number and severity of the patched issues (SecurityOnline). Palo Alto Networks also issued a security advisory (PAN-SA-2026-0007) referencing this CVE in the context of their products using the Chromium engine. Community reaction was generally focused on the scale of the update rather than this specific CVE in isolation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."