CVE-2026-5873 is an out-of-bounds memory vulnerability affecting Google Chrome versions prior to 147.0.7727.55, residing in the V8 JavaScript engine. A remote attacker can exploit this flaw by crafting a malicious HTML page to trigger arbitrary code execution within Chrome's sandbox environment. The vulnerability carries a HIGH severity rating from Chromium security analysts. The vulnerability presents a network-based attack vector with low complexity and no privilege requirements, requiring only user interaction to trigger exploitation. With a CVSS v3.1 score of 8.8, it poses significant risk across confidentiality, integrity, and availability, allowing attackers to potentially escape sandbox protections and compromise system security. Exploitation status indicates minimal active threat currently. The vulnerability has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, and it does not appear on active exploitation lists. The extremely low EPSS score of 0.001020000 suggests that real-world exploitation likelihood remains low at this time, though organizations should prioritize patching to Chrome 147.0.7727.55 or later as a preventive measure.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 147.0.7727.55CPE matchmatch criteria | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* | ||
>= 147.0.7727.55, < 147.0.7727.55CPE match | cpe:2.3:a:google:chrome:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.