
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5873 is an out-of-bounds read and write vulnerability in the V8 JavaScript engine of Google Chrome that allows a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. It affects all versions of Google Chrome prior to 147.0.7727.55, as well as Microsoft Edge (Chromium-based). The vulnerability was reported by Google's internal security team on March 25, 2026, and publicly disclosed on April 8, 2026, when Chrome 147.0.7727.55 was released. It carries a CVSS v3.1 base score of 8.8 (High) (Chrome Releases, GitHub Advisory).
The vulnerability is rooted in insufficient bounds checking within Chrome's V8 JavaScript engine, classified as CWE-125 (Out-of-bounds Read) and CWE-787 (Out-of-bounds Write). An attacker can exploit this by delivering a specially crafted HTML page that triggers memory access violations during JavaScript execution in V8, enabling arbitrary code execution within the Chrome sandbox. Exploitation requires user interaction — specifically, a victim must visit or be redirected to a malicious web page — but no authentication or special privileges are needed on the attacker's side. The Chromium issue tracker references bug ID 496301615 for this vulnerability (Chrome Releases, GitHub Advisory).
Successful exploitation allows an attacker to execute arbitrary code within the Chrome browser sandbox, with high impact to confidentiality, integrity, and availability of the browser process. An attacker could access sensitive user data such as credentials, session tokens, and browsing history stored within the browser context, and potentially establish persistent access. While the sandbox limits direct OS-level compromise, chaining this vulnerability with a sandbox escape could lead to full system compromise (GitHub Advisory, Feedly).
cmd.exe, /bin/sh, powershell.exe); Chrome renderer processes consuming abnormally high memory or CPU.Google has released Chrome 147.0.7727.55 (Linux) and 147.0.7727.55/56 (Windows/Mac) which resolves this vulnerability; users should update immediately (Chrome Releases). Microsoft has also released a security update for Edge (Chromium-based) addressing this issue (Microsoft MSRC). Enabling automatic browser updates is the most effective mitigation. As a temporary workaround where updates cannot be immediately deployed, organizations should restrict user access to untrusted or unknown websites and consider using browser isolation technologies. Linux distributions including Debian, openSUSE, and Fedora have also released updated Chromium packages.
The vulnerability attracted notable attention due to a researcher's public claim that the Claude Opus AI model was used to assist in building a working Chrome exploit chain targeting this CVE, sparking broad discussion about AI-assisted vulnerability research and the "deskilling paradox" in offensive security (Hacktron AI, Signal Intent). Security news outlets including The Hacker News, GBHackers, and CyberSecurityNews covered both the Chrome patch release and the AI-assisted exploit story (GBHackers). The story was also discussed on Lobste.rs and picked up in multiple weekly security recaps, reflecting significant community interest in the implications of LLM-assisted exploit development (Cybernoz).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."