
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5861 is a use-after-free vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It was reported by researcher "5shain" on 2026-02-23 and publicly disclosed on 2026-04-08 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based) builds based on the same engine. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-416 (Use After Free), occurring within Chrome's V8 JavaScript engine. A use-after-free condition arises when V8 references or operates on memory that has already been freed, potentially allowing an attacker to control the reused memory region and redirect execution flow. Exploitation requires a victim to visit a specially crafted HTML page, which triggers the memory corruption in the V8 engine. The bug was tracked internally as Chromium issue #486927780 and awarded a $3,000 bug bounty reward (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome sandbox environment, resulting in high confidentiality, integrity, and availability impacts on the affected browser process. While execution is constrained to the sandbox, this class of vulnerability is frequently chained with sandbox escape bugs to achieve full system compromise. All users running Google Chrome prior to 147.0.7727.55 or unpatched Chromium-based Microsoft Edge versions are at risk (GitHub Advisory, Chrome Release).
chrome.exe / chrome on Linux/Mac) spawning unexpected child processes or making unusual system calls inconsistent with normal browser activity.Update Google Chrome to version 147.0.7727.55 or later on all platforms (Windows, Mac, Linux); the patch was released on April 7, 2026 (Chrome Release). Microsoft Edge (Chromium-based) users should apply the corresponding security update from Microsoft (Microsoft MSRC). As a temporary measure, organizations should enable automatic browser updates, restrict access to untrusted or unknown websites via web content filtering, and monitor for exploitation attempts using Nessus detection IDs 305628, 305629, 305731, 306340, and Qualys detection ID 386995.
The Chrome 147 update was covered by several cybersecurity news outlets including GBHackers, CyberSecurityNews, and CyberPress, which highlighted the broader release patching 60 vulnerabilities including two critical WebML flaws alongside CVE-2026-5861. The update was also noted in Linux distribution security advisories for Debian and openSUSE, reflecting the broad ecosystem impact of Chromium-based browser patches. No notable individual researcher commentary or significant social media controversy specific to CVE-2026-5861 has been identified beyond standard patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."