CVE-2026-5871
vulnerability analysis and mitigation

Overview

CVE-2026-5871 is a Type Confusion vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It was reported by Google on 2026-03-24 and publicly disclosed on 2026-04-01 as part of the Chrome 147 stable channel release. Affected versions include all Google Chrome releases prior to 147.0.7727.55, as well as Microsoft Edge Chromium (Chromium-based). It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Release, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-843 (Access of Resource Using Incompatible Type / 'Type Confusion'), occurring within Chrome's V8 JavaScript engine (Chromium issue #495679730). Type confusion bugs in V8 arise when the engine incorrectly assumes the type of a JavaScript object, allowing an attacker to craft JavaScript that causes V8 to treat memory regions as different object types than intended, potentially enabling controlled memory reads/writes. Exploitation requires user interaction — specifically, a victim visiting a malicious HTML page — but no authentication or special privileges are needed on the attacker's side (Chrome Release, GitHub Advisory).

Impact

Successful exploitation allows a remote attacker to execute arbitrary code within the Chrome renderer sandbox, with high impact on confidentiality, integrity, and availability of the affected browser process. While execution is constrained to the sandbox, this class of vulnerability is frequently chained with a sandbox escape to achieve full system compromise. All users running Google Chrome prior to 147.0.7727.55 or unpatched versions of Microsoft Edge Chromium on Windows, Mac, and Linux are at risk (GitHub Advisory, Chrome Release).

Exploitation steps

  1. Reconnaissance: Identify targets running Google Chrome versions prior to 147.0.7727.55 or unpatched Microsoft Edge Chromium builds.
  2. Craft malicious HTML page: Develop a crafted HTML/JavaScript page that triggers the type confusion condition in V8 by manipulating JavaScript object types in a way that causes V8 to misinterpret memory layout.
  3. Deliver the payload: Host the malicious page on an attacker-controlled server and lure the victim to visit it via phishing, malvertising, or a compromised website.
  4. Trigger type confusion: When the victim's browser processes the crafted JavaScript, V8 accesses a memory resource using an incompatible type, enabling controlled memory corruption within the renderer process.
  5. Achieve sandbox code execution: Leverage the memory corruption to execute arbitrary code within the Chrome renderer sandbox, potentially as a stepping stone to a full sandbox escape via a chained vulnerability (Chrome Release, GitHub Advisory).

Mitigation and workarounds

Update Google Chrome to version 147.0.7727.55 or later (147.0.7727.55 for Linux; 147.0.7727.55/56 for Windows/Mac), which was released on April 1, 2026 and addresses this vulnerability. Microsoft Edge Chromium users should apply the latest available Edge update addressing this issue. As a general precaution, organizations should restrict access to untrusted websites and implement web content filtering where applicable. No configuration-based workaround is available; patching is the only definitive remediation (Chrome Release, Microsoft MSRC).

Community reactions

Security news outlets including GBHackers and CyberSecurityNews covered the Chrome 147 update, highlighting the multiple high-severity vulnerabilities patched in this release, including CVE-2026-5871. The broader security community noted the unusually large number of fixes (60+ vulnerabilities) in this release cycle. No notable individual researcher commentary specific to CVE-2026-5871 has been identified beyond standard patch reporting.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management