CVE-2026-5865: Type Confusion in V8
Chromium: CVE-2026-5865 Type Confusion in V8
Other sources
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see Google Chrome Releases for more information.
— Microsoft
Type Confusion in V8 in Google Chrome prior to 147.0.7727.55 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
— MITRE
Credit
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 147.0.7727.55 - Upgrade
Upgrade
Google Chrome/Chromium (V8)to a version that resolves this vulnerability.Fixed in 147.0.7727.55 - Compensating control
Limit exposure by preventing remote clients from loading untrusted HTML/web content (e.g., restrict or isolate browsing sessions that can load attacker-controlled pages) until the browser is updated to a non-vulnerable version.
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
- CVE-2026-5858
- CVE-2026-5859
- CVE-2026-5860
- CVE-2026-5861
- CVE-2026-5862
- CVE-2026-5863
- CVE-2026-5864
- CVE-2026-5866
- CVE-2026-5867
- CVE-2026-5868
- CVE-2026-5869
- CVE-2026-5870
- CVE-2026-5871
- CVE-2026-5872
- CVE-2026-5873
- CVE-2026-5874
- CVE-2026-5875
- CVE-2026-5876
- CVE-2026-5877
- CVE-2026-5878
- CVE-2026-5879
- CVE-2026-5880
- CVE-2026-5881
- CVE-2026-5882
- CVE-2026-5883
- CVE-2026-5884
- CVE-2026-5885
- CVE-2026-5886
- CVE-2026-5887
- CVE-2026-5888
- CVE-2026-5889
- CVE-2026-5890
- CVE-2026-5891
- CVE-2026-5892
- CVE-2026-5893
- CVE-2026-5894
- CVE-2026-5895
- CVE-2026-5896
- CVE-2026-5897
- CVE-2026-5898
- CVE-2026-5899
- CVE-2026-5900
- CVE-2026-5901
- CVE-2026-5902
- CVE-2026-5903
- CVE-2026-5905
- CVE-2026-5906
- CVE-2026-5907
- CVE-2026-5908
- CVE-2026-5909
- CVE-2026-5910
- CVE-2026-5911
- CVE-2026-5912
- CVE-2026-5913
- CVE-2026-5914
- CVE-2026-5915
- CVE-2026-5918
- CVE-2026-5919
Frequently Asked Questions
What is the severity of CVE-2026-5865?
CVE-2026-5865 is rated as a high severity vulnerability due to the potential for exploitation leading to type confusion in V8.
How do I fix CVE-2026-5865?
To fix CVE-2026-5865, update Google Chrome to version 147.0.7727.55 or later, or ensure your Microsoft Edge is up to date.
Which browsers are affected by CVE-2026-5865?
Both Google Chrome versions prior to 147.0.7727.55 and Microsoft Edge (Chromium-based) are affected by CVE-2026-5865.
What is the nature of the vulnerability described in CVE-2026-5865?
CVE-2026-5865 involves type confusion in the V8 JavaScript engine, which could lead to various security risks.
Is my operating system affected by CVE-2026-5865?
No, CVE-2026-5865 specifically affects the browser software and not the underlying operating systems like Windows, macOS, or Linux.