CVE-2026-5862
published 2026-04-08CVE-2026-5862: Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted…
high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | chromium | < chromium 147.0.7727.55-1 (sid) | chromium 147.0.7727.55-1 (sid) |
| chrome | < 147.0.7727.55 | 147.0.7727.55 | |
| chrome | >= 147.0.7727.55 < 147.0.7727.55 | 147.0.7727.55 | |
| chrome_chrome | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
osv8.8HIGH
Chrome
Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5862
vendor_chrome·2026-04-22·CVSS 8.8
CVE-2026-5862 [HIGH] Stable Channel Update for ChromeOS / ChromeOS Flex: CVE-2026-5862
Stable Channel Update for ChromeOS / ChromeOS Flex
CVE-2026-5862
Chrome
Stable Channel Update for Desktop: CVE-2026-5861
vendor_chrome·2026-04-07·CVSS 8.8
CVE-2026-5861 [HIGH] Stable Channel Update for Desktop: CVE-2026-5861
Stable Channel Update for Desktop
CVE-2026-5861: Use after free in V8. Reported by 5shain on 2026-02-23 [TBD][ 470566252 ] High CVE-2026-5862: Inappropriate implementation in V8
Reported by Google on 2025-12-21 [TBD][ 484527367 ] High CVE-2026-5863: Inappropriate implementation in V8
Severity: high
Red Hat
chromium-browser: Inappropriate implementation in V8
vendor_redhat·2026-04-07·CVSS 8.8
CVE-2026-5862 [HIGH] CWE-130 chromium-browser: Inappropriate implementation in V8
chromium-browser: Inappropriate implementation in V8
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
An inappropriate implementation flaw was found in the V8 component of the Chromium browser.
Upstream bug(s):
https://code.google.com/p/chromium/issues/detail?id=470566252
Statement: Red Hat Product Security rates the severity of this flaw as determined by the Google Chrome Security Advisory.
Debian
CVE-2026-5862: chromium - Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow...
vendor_debian·2026·CVSS 8.8
CVE-2026-5862 [HIGH] CVE-2026-5862: chromium - Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allow...
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Scope: local
bookworm: open
bullseye: open
forky: open
sid: resolved (fixed in 147.0.7727.55-1)
trixie: open
GHSA
GHSA-rfr9-hj39-mwqc: Inappropriate implementation in V8 in Google Chrome prior to 147
ghsa_unreviewed·2026-04-09
CVE-2026-5862 GHSA-rfr9-hj39-mwqc: Inappropriate implementation in V8 in Google Chrome prior to 147
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
VulDB
Google Chrome up to 146.0.7680.178 V8 sandbox (ID 470566 / WID-SEC-2026-1030)
vuldb·2026-04-09·CVSS 8.8
CVE-2026-5862 [HIGH] Google Chrome up to 146.0.7680.178 V8 sandbox (ID 470566 / WID-SEC-2026-1030)
A vulnerability identified as critical has been detected in Google Chrome. The impacted element is an unknown function of the component V8. This manipulation causes sandbox issue.
This vulnerability is tracked as CVE-2026-5862. The attack is possible to be carried out remotely. No exploit exists.
You should upgrade the affected component.
OSV
CVE-2026-5862: Inappropriate implementation in V8 in Google Chrome prior to 147
osv·2026-04-08·CVSS 8.8
CVE-2026-5862 [HIGH] CVE-2026-5862: Inappropriate implementation in V8 in Google Chrome prior to 147
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
No detection rules found.
No public exploits indexed.
Sans Isc
Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
blogs_sans_isc·2026-04-14·CVSS 8.8
[HIGH] Microsoft Patch Tuesday April 2026., (Tue, Apr 14th)
Microsoft Patch Tuesday April 2026.
Published: 2026-04-14. Last Updated: 2026-04-14 17:46:09 UTC
by Johannes Ullrich (Version: 1)
0 comment(s)
This month's Microsoft Patch Tuesday looks like a record one, but let's look at it a bit closer to understand what is happening
The update patches a total of 243 vulnerabilities. However, 78 of them are Chromium issues affecting Microsoft Edge. Patches for Edge were released earlier. This leaves 165 vulnerabilities that are not Edge-related. Of these, 8 are rated critical, and 154 are important. One vulnerability has already been exploited, and another was made public before today but has not yet been seen in the wild.
Noteworthy Vulnerabilities:
CVE-2026-33827 (Windows TCP/IP Remote Code Execution Vulnerability): As a packet nerd, I love thes
Wiz
CVE-2026-5862 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.8
CVE-2026-5862 [HIGH] CVE-2026-5862 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-5862 :
Google Chrome vulnerability analysis and mitigation
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
Source : NVD
Published April 8, 2026
CNA Score N/A
Affected Technologies
Google Chrome
Chromium
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 11.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
chromium
cpe:2.3:a:google:chrome
Sources
NVD
Debian 11, 12, 13, 14 No Fix Added at: Apr 09, 2026
Echo No Fix Added at: Apr 09, 2026
Linux Has Fix Added at: Apr 09, 2026
Windows Has Fix Added at: A
Bugzilla
CVE-2026-5862 chromium-browser: Inappropriate implementation in V8
bugzilla·2026-04-08·CVSS 8.8
CVE-2026-5862 [HIGH] CVE-2026-5862 chromium-browser: Inappropriate implementation in V8
CVE-2026-5862 chromium-browser: Inappropriate implementation in V8
Inappropriate implementation in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
2026-04-08
Published