
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5865 is a Type Confusion vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside the browser sandbox via a crafted HTML page. It was reported by Project WhatForLunch (@pjwhatforlunch) on March 12, 2026, and publicly disclosed on April 8, 2026, as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55; Microsoft Edge (Chromium-based) is also affected. The vulnerability carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), rooted in the V8 JavaScript engine's Maglev JIT compiler incorrectly handling phi node untagging operations. When V8 processes certain JavaScript constructs, it may assign an incorrect type to a value, leading to memory corruption when that value is subsequently accessed under the wrong type assumption. Exploitation requires the victim to visit a malicious or attacker-controlled HTML page, making user interaction a prerequisite. A technical write-up detailing the V8 Maglev incorrect phi untagging root cause has been published by Nebusec (Nebusec Research, Chrome Releases).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, potentially leading to data theft, malware installation, or further system compromise if combined with a sandbox escape. The vulnerability affects confidentiality, integrity, and availability at a high level, as an attacker gaining code execution within the sandbox can access browser session data, credentials stored in the browser, and browsing history. While the sandbox limits direct OS-level impact, chaining this vulnerability with a sandbox escape could result in full system compromise (GitHub Advisory, Chrome Releases).
chrome.exe / chrome on Linux/Mac) spawning unexpected child processes or exhibiting anomalous memory usage; unusual subprocesses launched by the browser sandbox.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which addresses this vulnerability; users should update immediately via Chrome's built-in update mechanism or by downloading from the official Chrome website. Microsoft has released a corresponding patch for Edge (Chromium-based); users should apply the latest Edge update. As a temporary workaround, organizations can enforce browser security policies that restrict JavaScript execution on untrusted sites, or consider disabling the Maglev JIT compiler via enterprise policy flags until patching is complete. Users should also be educated to avoid clicking suspicious links or visiting untrusted websites (Chrome Releases, Microsoft MSRC).
The Chrome 147 update was covered by security news outlets including GBHackers and CyberSecurityNews, which highlighted the batch of 60+ vulnerabilities patched in this release, including CVE-2026-5865 (GBHackers, CyberSecurityNews). The SANS Internet Storm Center also noted the release in its diary (SANS ISC). Nebusec published a detailed technical research post on the V8 Maglev incorrect phi untagging root cause, which attracted attention from the security research community (Nebusec Research). Community sentiment reflects routine concern about V8 type confusion bugs given their historical exploitation potential, though no active exploitation has been reported.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."