
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5279 is an object corruption vulnerability in the V8 JavaScript engine in Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It affects all Google Chrome versions prior to 146.0.7680.177/178 (Windows/Mac) and 146.0.7680.177 (Linux), as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Hyeonjun Ahn (@_deayzl) on March 8, 2026, and patched on March 31, 2026, with public disclosure on April 1, 2026. It carries a CVSS v3.1 base score of 8.8 (High) per Feedly/NVD, though the GitHub Advisory Database rates it 6.3 (Moderate) (Chrome Release Blog, GitHub Advisory).
The vulnerability is rooted in object corruption within Chrome's V8 JavaScript engine (CWE-120: Buffer Copy without Checking Size of Input / Classic Buffer Overflow), where improper handling of internal V8 objects can lead to memory corruption. An attacker exploits this by serving a specially crafted HTML page that triggers the corruption when processed by V8, enabling arbitrary code execution within the Chrome sandbox. Exploitation requires no special privileges but does require user interaction — specifically, a victim visiting a malicious web page. The Chromium bug tracker references issue #490642836, though full technical details remain restricted pending broad user patching (Chrome Release Blog, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome browser sandbox, which could lead to compromise of user data, credential theft, and potential sandbox escape for further system compromise. The vulnerability affects confidentiality, integrity, and availability at a high level (per CVSS v3.1 scoring), impacting any user running a vulnerable Chrome or Chromium-based browser version. While execution is constrained to the sandbox, chaining this with a sandbox escape vulnerability could result in full system compromise (GitHub Advisory, Feedly).
cmd.exe, powershell.exe, /bin/sh, curl, wget); Chrome renderer processes consuming abnormally high memory or CPU.Google released the fix in Chrome stable channel version 146.0.7680.177 (Linux) and 146.0.7680.178 (Windows/Mac), published March 31, 2026. Users should update Chrome immediately via Settings > Help > About Google Chrome, or enable automatic updates. Microsoft Edge (Chromium-based) users should also apply the corresponding Edge update. As a temporary workaround, organizations can restrict access to untrusted websites and implement user training to avoid clicking suspicious links, since user interaction is required for exploitation (Chrome Release Blog, Microsoft MSRC).
The March 31, 2026 Chrome update received significant media attention primarily due to the co-patched CVE-2026-5281 (actively exploited zero-day in Dawn), with outlets such as GBHackers, CyberSecurityNews, The Hacker News, and Forbes covering the release under headlines referencing a Chrome zero-day under active exploitation. CVE-2026-5279 was covered as part of the broader 21-fix update but was not individually highlighted as actively exploited. The CIS issued an advisory noting multiple vulnerabilities in Google Chrome could allow arbitrary code execution. Qualys and Tenable both published detection plugins for the vulnerability shortly after disclosure (Chrome Release Blog, CIS Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."