CVE-2026-1862 is a high-severity type confusion vulnerability in Google Chrome's V8 JavaScript engine, affecting various operating systems including Apple, Google, Linux, and Microsoft. A remote attacker could exploit this flaw by enticing a user to visit a specially crafted HTML page, potentially leading to heap corruption. With a CVSS score of 8.8, this vulnerability presents a high risk of impact to confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant media coverage and community discussion, indicating its importance to security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 144.0.7559.132, < 144.0.7559.132CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
< 144.0.7559.132CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.