CVE-2026-5863 is a high-severity vulnerability in Google Chrome's V8 JavaScript engine affecting versions prior to 147.0.7727.55. An inappropriate implementation flaw allows remote attackers to execute arbitrary code within the browser sandbox through crafted HTML pages, potentially compromising system integrity and confidentiality. This vulnerability represents a significant browser security risk as it requires only user interaction with a malicious webpage to trigger exploitation. The vulnerability carries a CVSS score of 8.8 (High), indicating significant severity with a network-based attack vector requiring no special privileges and minimal user interaction. The attack has high impact across confidentiality, integrity, and availability, though exploitation is contained within the sandbox environment. The EPSS score of 0.001020 suggests relatively low probability of exploitation in the wild compared to other CVEs, and the vulnerability is not currently listed on the CISA Known Exploited Vulnerabilities catalog. Currently, there is no evidence of active exploitation in the wild, and the vulnerability maintains an inactive status on threat tracking lists. While the FAUCET Risk Score of 42.0 indicates moderate concern, the low EPSS and absence of public exploit code suggest limited immediate threat. Organizations should prioritize patching to version 147.0.7727.55 or later as part of standard update cycles, though emergency mitigation measures are not immediately warranted based on current exploitation data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.