
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5871 is a Type Confusion vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It was reported by Google on 2026-03-24 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55, as well as Microsoft Edge Chromium (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).
The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), occurring within Chrome's V8 JavaScript engine (Chromium issue #495679730). Type confusion bugs in V8 arise when the engine incorrectly assumes the type of a JavaScript object, allowing an attacker to craft JavaScript that causes V8 to treat memory regions as different object types than intended, potentially enabling controlled memory reads/writes. Exploitation requires user interaction — specifically, a victim visiting a malicious HTML page — but no authentication or special privileges are needed on the attacker's side (Chrome Release, GitHub Advisory).
Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, with high impact on confidentiality, integrity, and availability of the affected browser process. While execution is constrained to the sandbox, this class of vulnerability is frequently chained with a sandbox escape to achieve full system compromise. All users running Google Chrome prior to 147.0.7727.55 or unpatched versions of Microsoft Edge Chromium on Windows, Mac, and Linux are at risk (GitHub Advisory, Chrome Release).
Update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55 for Linux; 147.0.7727.55/56 for Windows/Mac), which was released on April 1, 2026 and addresses this vulnerability. Microsoft Edge Chromium users should apply the latest available Edge update addressing this issue. As a general precaution, organizations should restrict access to untrusted websites and implement web content filtering where applicable. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Release, Microsoft MSRC).
Security news outlets including GBHackers and CyberSecurityNews covered the Chrome 147 update, highlighting the multiple high-severity vulnerabilities patched in this release, including CVE-2026-5871. The broader security community noted the unusually large number of fixes (60+ vulnerabilities) in this release cycle. No notable individual researcher commentary specific to CVE-2026-5871 has been identified beyond standard patch reporting.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."